我的笔记本中了WINDOWS下的PE病毒病毒名称 Trojan.DL.Delf.eoa ,用瑞星只能检查说重启删除,可是重启了还有.病毒文件在:C:\Documents and Settings\All Users\Application Data\Microsoft\UserData目录里.在目录下删除不了.
请知道的教下我.谢谢!
2006-12-17,23:34:07
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<igfxtray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation]
<igfxhkcmd><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation]
<igfxpers><C:\WINDOWS\system32\igfxpers.exe> [(Verified)Intel Corporation]
<High Definition Audio Property Page Shortcut><CHDAudPropShortcut.exe> [(Verified)Windows (R) Server 2003 DDK provider]
<DetectorApp><C:\Program Files\Sonic\DigitalMedia Plus v7\MyDVD Plus\DetectorApp.exe> [N/A]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Synaptics, Inc.]
<hpWirelessAssistant><C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe> [Hewlett-Packard Development Company, L.P.]
<HP Software Update><C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.]
<eabconfg.cpl><C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start> [Hewlett-Packard ]
<Cpqset><C:\Program Files\HPQ\Default Settings\cpqset.exe> [N/A]
<SunJavaUpdateSched><C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe> [Sun Microsystems, Inc.]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<miniqqlive><"C:\Documents and Settings\wang\桌面\MiniQQLive.exe"> [N/A]
<fenglei><F:\flmpc\fengleiLive.exe> [风雷影音工作室]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [N/A]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"f:\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
<YahooC:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll533937><regsvr32 /s C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll> [(Verified)YAHOO Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll> [(Verified)YAHOO Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
<WinlogonNotify: igfxcui><igfxdev.dll> [(Verified)Intel Corporation]
==================================
启动文件夹
[QQ游戏启动加速程序]
<C:\Documents and Settings\wang\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> F:\工具\QQ\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
==================================
服务
[Application Management / AppMgmt]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[HP WMI Interface / hpqwmi]
<C:\Program Files\HPQ\Shared\hpqwmi.exe><Hewlett-Packard Development Company, L.P.>
[hpqwmiex / hpqwmiex]
<C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe><Hewlett-Packard Development Company, L.P.>
[LightScribeService Direct Disc Labeling Service / LightScribeService]
<"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[Rising Process Communication Center / RsCCenter]
<"f:\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"f:\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[USBDeviceService / USBDeviceService]
<C:\Program Files\Sonic\DigitalMedia Plus v7\MyDVD Plus\USBDeviceService.exe><>
==================================
驱动程序
[AliIde / AliIde]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[WIDCOMM USB Bluetooth Driver / BTWUSB]
<System32\Drivers\btwusb.sys><Broadcom Corporation.>
[d347bus / d347bus]
<\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[Intel(R) PRO Network Connection Driver / E100B]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[eabfiltr / eabfiltr]
<\??\C:\WINDOWS\system32\drivers\EABFiltr.sys><Hewlett-Packard Development Company, L.P.>
[eabusb / eabusb]
<\??\C:\WINDOWS\system32\drivers\eabusb.sys><Hewlett-Packard Development Company, L.P.>
[EagleNT / EagleNT]
<\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[ExpScaner / ExpScaner]
<\??\f:\Rising\Rav\ExpScan.sys><>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService]
<system32\drivers\CHDAud.sys><Conexant Systems Inc.>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HookCont / HookCont]
<\??\f:\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg]
<\??\f:\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\f:\Rising\Rav\HookSys.sys><Rising>
[HSFHWAZL / HSFHWAZL]
<system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV]
<system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[ialm / ialm]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Intel AHCI Controller / iaStor]
<\SystemRoot\System32\DRIVERS\iaStor.sys><Intel Corporation>
[mdmxsdk / mdmxsdk]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[MEMSCAN / MEMSCAN]
<\??\f:\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[HP Webcam 1000 / Mvc25U870_VID_1262&PID_25FD]
<System32\Drivers\Mvc25U870.sys><Micro Vision Co.,Ltd>
[npkcrypt / npkcrypt]
<\??\F:\工具\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[rimmptsk / rimmptsk]
<system32\DRIVERS\rimmptsk.sys><REDC>
[rimsptsk / rimsptsk]
<system32\DRIVERS\rimsptsk.sys><REDC>
[Ricoh xD-Picture Card Driver / rismxdp]
<system32\DRIVERS\rixdptsk.sys><REDC>
[RsNTGDI / RsNTGDI]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS]
<\??\f:\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[SKNFW / SKNFW]
<\??\C:\WINDOWS\system32\Drivers\SKNFW.sys><N/A>
[SMC IrCC Miniport Device Driver / SMCIRDA]
<system32\DRIVERS\smcirda.sys><SMC>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1]
<system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Synaptics TouchPad Driver / SynTP]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[ViaIde / ViaIde]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51]
<system32\DRIVERS\w39n51.sys><Intel? Corporation>
[winachsf / winachsf]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[World Standard Teletext Codec / WSTCODEC]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
==================================
浏览器加载项
N/A
==================================
正在运行的进程
N/A
==================================
文件关联
N/A
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================