瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助,已经2天了,还是没搞定。应该是新变种的。

1   1  /  1  页   跳转

求助,已经2天了,还是没搞定。应该是新变种的。

求助,已经2天了,还是没搞定。应该是新变种的。

系统是2000,症状为一开机即打开iexplore.exe(该进程在任务管理器中为大写,并且不能停止,进程来源为c:\program files\Internet Explorer\iexplore.exe,看上去是正常文件)。每过3到5秒,该进程即占用cpu100%,2秒后停止cpu占用。占用cpu100%时系统中杀毒软件停止响应但并不关闭(江民、瑞星、诺顿全是这样,顺便说下,全部是正版的,单位比较有钱,没办法)。
尝试过ghost恢复,但每次恢复后进入到系统后第一次重新启动后启动过程极长,并且启动后杀毒服务全部停止,启动到桌面后explorer.exe出错一次,但马上恢复。ghost是3个月前的备份,做备份时并无该情况。
将c:\program files\Internet Explorer\iexplore.exe更名为c:\program files\Internet Explorer\iexplore.bak,重新启动后该进程消失,但是explorer.exe进程马上就接替了原来iexplore.exe进程的工作,每过3到5秒,该进程即占用cpu100%,2秒后停止cpu占用。占用cpu100%时系统中杀毒软件停止响应但并不关闭。
我已经尝试很多办法,但都不能解决问题。
所以上来求教。
系统非常重要,不能重新安装!!!!
以下是HijackThis.exe的扫描结果:
Logfile of HijackThis v1.99.1
Scan saved at 13:24:13, on 2006-9-15
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\SafeSignCertReg.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
C:\WINNT\System32\taskmgr.exe
C:\Program Files\My444IEGB\MyIE.exe
D:\TDdownload\HijackThis.exe

O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CertificateRegistration] SafeSignCertReg.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: 豪杰超级解霸9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Program Files\Herosoft\Hero 9\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Program Files\Herosoft\Hero 9\STHSDVD.EXE
O9 - Extra button: 讯通视频语音聊天 - {97C0CDFA-970D-4222-ADDE-6718E89E887C} - http://www.bdsystem.com/ (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O16 - DPF: {0400AC1C-EEF0-4638-A501-31D5A0DC2002} (VTPlug3 Class) - http://s4.liaoliao.com:1995/VTrans.cab
O16 - DPF: {098A3F72-3110-4004-B954-2F9DC44934B4} (AddSHCARoot Control) - http://tt.xixiliao.com:88/xixiliao/chat/BDC_Root_CA.cab
O16 - DPF: {0EB487C8-E9AC-43A6-8C4C-083999B0622F} (InfosecCertInstall Class) - https://mybank.icbc.com.cn/icbc/perbank/certInStall.dll
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://www.123liao.com/talk.cab
O16 - DPF: {7253A666-8D4A-11D7-A4DC-00E04C504779} (BDC Control) - http://ct.moqiliao.com/BDC.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} - http://jump.cnnic.cn/stat/stat?sid=0008&debug=false&pid=c_admin88&url=http://client.jogo.cn/download/cnnic/cdn.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {DA215190-98B2-47DE-AE24-DA95481DFFBA} (AxUSBKey Class) - https://mybank.icbc.com.cn/icbc/perbank/AxUSBKey.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{1ACEAB28-CE1B-4B21-93CF-96BEC91D8BE3}: NameServer = 61.187.98.3,61.187.99.3
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus 自动防护服务 (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows Share Device Manager (wsdmsowrk) - Unknown owner -
最后编辑2006-09-15 13:52:07
分享到:
gototop
 

以下是SREngLOG.log
2006-09-15,13:46:07

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 2 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <CertificateRegistration><SafeSignCertReg.exe>  [A.E.T. Europe B.V.]
    <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <ccApp><C:\Program Files\Common Files\Symantec Shared\ccApp.exe>  [Symantec Corporation]
    <ccRegVfy><C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe>  [Symantec Corporation]
    <Symantec NetDriver Monitor><C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer>  [Symantec Corporation]
    <SSC_UserPrompt><C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe>  [Symantec Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <CheckFaultKernel><C:\WINNT\System32\mswdm.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\Program Files\Herosoft\Hero 9\解霸屏保.SCR>  []

==================================
启动文件夹
服务
[Symantec Event Manager / ccEvtMgr]
  <C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe><Symantec Corporation>
[Symantec Password Validation Service / ccPwdSvc]
  <C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe><Symantec Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Norton AntiVirus 自动防护服务 / navapsvc]
  <C:\Program Files\Norton AntiVirus\navapsvc.exe><Symantec Corporation>
[ScriptBlocking Service / SBService]
  <C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc]
  <C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe><Symantec Corporation>
[SymWMI Service / SymWSC]
  <C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe><Symantec Corporation>

==================================
浏览器加载项
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[CNavExtBho Class]
  {BDF3E430-B101-42AD-A544-FADC6B084872} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[豪杰超级解霸9]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\Program Files\Herosoft\Hero 9\STHSDVD.EXE, herosoft>
[讯通视频语音聊天]
  {97C0CDFA-970D-4222-ADDE-6718E89E887C} <http://www.bdsystem.com/, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[Norton AntiVirus]
  {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[VTPlug3 Class]
  {0400AC1C-EEF0-4638-A501-31D5A0DC2002} <C:\WINNT\System32\gxd\VTrans3.dll, >
[AddSHCARoot Control]
  {098A3F72-3110-4004-B954-2F9DC44934B4} <C:\WINNT\DOWNLO~1\ADDCAR~1.OCX, SHECA>
[InfosecCertInstall Class]
  {0EB487C8-E9AC-43A6-8C4C-083999B0622F} <C:\WINNT\Downloaded Program Files\certInStall.dll, >
[IMCv1 Control]
  {6924091F-CD97-41E1-B1D4-D9079409D413} <C:\PROGRA~1\LtUcx\1003\c0.dll, N/A>
[BDC Control]
  {7253A666-8D4A-11D7-A4DC-00E04C504779} <C:\PROGRA~1\BDC\Bdc.ocx, BLUE>
[AxSubmitControl Class]
  {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINNT\DOWNLO~1\SUBMIT~1.DLL, >
[IEDown Class]
  {D0A29C6C-AA71-4423-8C4A-5998B774C448} <C:\WINNT\System32\GLIEDown2.dll, N/A>
[AxUSBKey Class]
  {DA215190-98B2-47DE-AE24-DA95481DFFBA} <C:\WINNT\DOWNLO~1\USBKey.dll, >
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 152][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.2901>
[PID: 180][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.2581>
[PID: 200][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.2953>
[PID: 228][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.2780>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.2778.297.3>
[PID: 240][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.2964>
[PID: 364][C:\WINNT\System32\SCardSvr.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 444][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 496][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe]  <Symantec Corporation><1.00.37>
    [C:\WINNT\system32\ccTrust.dll]  <Symantec Corporation><1.00.22>
    [C:\WINNT\system32\SYMSTORE.dll]  <Symantec Corporation><4.7.2.15>
    [C:\PROGRA~1\NORTON~1\NAVEvent.dll]  <Symantec Corporation><9.00.1106>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ccEvt.dll]  <Symantec Corporation><1.00.106>
[PID: 576][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2161.1>
[PID: 608][C:\WINNT\System32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 628][C:\Program Files\Norton AntiVirus\navapsvc.exe]  <Symantec Corporation><9.00.1106>
    [C:\Program Files\Norton AntiVirus\SavRT32.dll]  <Symantec Corporation><9.0.1.36>
[PID: 740][C:\WINNT\system32\regsvc.exe]  <Microsoft Corporation><5.00.2195.2104>
[PID: 468][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.1>
[PID: 900][C:\WINNT\system32\stisvc.exe]  <Microsoft Corporation><5.00.2195.2104>
[PID: 952][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0029>
[PID: 1132][C:\WINNT\Explorer.EXE]  <Microsoft Corporation><5.00.3315.2846>
    [C:\WINNT\svhosts.DLL]  <N/A><N/A>
    [C:\WINNT\System32\igfxpph.dll]  <Intel Corporation><3,0,0,1847>
    [C:\WINNT\System32\hccutils.DLL]  <Intel Corporation><3,0,0,1847>
    [C:\WINNT\System32\igfxres.dll]  <Intel Corporation><3,0,0,1847>
    [C:\WINNT\System32\igfxsrvc.dll]  <Intel Corporation><3,0,0,1847>
    [C:\WINNT\System32\igfxdev.dll]  <Intel Corporation><3,0,0,1847>
    [C:\PROGRA~1\baidu\bar\baidubar.dll]  <Baidu.com, Inc.><2, 0, 2, 99>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\Program Files\Norton AntiVirus\NavShExt.dll]  <Symantec Corporation><9.00.02>
    [C:\WINNT\System32\ccTrust.dll]  <Symantec Corporation><1.00.22>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><1, 1, 0, 126>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><1, 1, 0, 126>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\qdshm.dll]  <><1, 0, 101, 20>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll]  <Gabest><1, 0, 0, 9>
    [C:\WINNT\System32\ffdshow.ax]  <N/A><1, 0, 0, 1>
    [C:\WINNT\System32\msdmo.dll]  <N/A><N/A>
[PID: 1152][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3427>
[PID: 660][C:\WINNT\System32\SafeSignCertReg.exe]  <A.E.T. Europe B.V.><2.0.0.2>
[PID: 1236][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  <Symantec Corporation><1.00.106>
    [C:\WINNT\System32\SYMSTORE.dll]  <Symantec Corporation><4.7.2.15>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL]  <Symantec Corporation><1.00.106>
    [C:\WINNT\System32\SYMREDIR.dll]  <Symantec Corporation><5.5.1.6>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ccErrDsp.DLL]  <Symantec Corporation><1.00.106>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCREGMON.DLL]  <Symantec Corporation><1.00.106>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ccEvt.DLL]  <Symantec Corporation><1.00.106>
    [C:\WINNT\System32\ccTrust.dll]  <Symantec Corporation><1.00.22>
    [C:\PROGRA~1\NORTON~1\CCIMSCAN.DLL]  <Symantec Corporation><9.00.1106>
    [C:\PROGRA~1\NORTON~1\DEFALERT.DLL]  <Symantec Corporation><9.00.02>
    [C:\PROGRA~1\NORTON~1\NAVAPW32.DLL]  <Symantec Corporation><9.00.1106>
    [C:\WINNT\System32\ccPasswd.DLL]  <Symantec Corporation><1.00.106>
    [C:\PROGRA~1\NORTON~1\apwutil.dll]  <Symantec Corporation><9.00.1106>
    [C:\PROGRA~1\NORTON~1\SavRT32.dll]  <Symantec Corporation><9.0.1.36>
    [C:\Program Files\Norton AntiVirus\apwcmdnt.dll]  <Symantec Corporation><9.00.1106>
    [C:\Program Files\Norton AntiVirus\NavEmail.dll]  <Symantec Corporation><9.00.1106>
[PID: 1348][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  <Thunder Networking Technologies,LTD><5.3.0.220>
    [C:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
    [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 4, 71>
    [C:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  <><1, 0, 2, 1>
    [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  <N/A><N/A>
    [C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 15>
    [C:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 148>
    [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  <Thunder Networking Technologies,LTD><2, 1, 0, 18>
    [C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  < ><1, 0, 0, 11>
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll]  < ><2, 3, 0, 37>
    [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  <Thunder Networking Technologies,LTD><1, 0, 3, 8>
    [C:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 55>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><1, 1, 0, 126>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><1, 1, 0, 126>
    [C:\WINNT\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin07.dll]  <Thunder Networking Technologies,LTD><2, 3, 0, 49>
    [C:\WINNT\System32\wmp.ocx]  <N/A><N/A>
    [C:\WINNT\System32\wmpui.DLL]  <N/A><N/A>
    [C:\WINNT\System32\wmpcore.dll]  <N/A><N/A>
    [C:\WINNT\System32\wmpcd.dll]  <N/A><N/A>
    [C:\WINNT\System32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll]  <Gabest><1, 0, 0, 9>
    [C:\WINNT\System32\ffdshow.ax]  <N/A><1, 0, 0, 1>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\TTL2Dec.dll]  <N/A><N/A>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\Vid1Dec.dll]  <N/A><N/A>
[PID: 568][C:\WINNT\System32\taskmgr.exe]  <Microsoft Corporation><5.00.2137.1>
[PID: 1404][C:\Program Files\My444IEGB\MyIE.exe]  <MoreQuick><1, 0, 0, 0>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><1, 1, 0, 126>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><1, 1, 0, 126>
    [C:\WINNT\System32\UNISPIM5.IME]  <北京紫光华宇软件股份有限公司><5.0.0.5076>
    [C:\WINNT\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 296][C:\WINNT\system32\NOTEPAD.EXE]  <Microsoft Corporation><5.00.2140.1>
[PID: 1668][D:\TDdownload\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

最恐怖的是参照其他人提供的log,居然找不到不安全的地方。昏死!!!
谁来帮忙啊!!!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT