瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 搞得我好麻烦呀HELP!!Trojan-PSW.Win32.Magania.lc

1   1  /  1  页   跳转

搞得我好麻烦呀HELP!!Trojan-PSW.Win32.Magania.lc

搞得我好麻烦呀HELP!!Trojan-PSW.Win32.Magania.lc

文件: C:\WINDOWS\uninstall\rundl13
中了这个木马为什么整个硬盘可执行文件EXE全都不行了,一进任何一个文件夹里有EXE的文件,就给卡巴删了,大家要帮帮我呀
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\Ringz Studio\mplayerc.exe    5 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\AOA\unins000.exe    699.4 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\AOA\OptimizePkgSys.exe    282.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\AOA\AOA.exe    1.7 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\AOA\AOA\core.exe    98.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\Program Files\Optic\神泣\Updater.exe    1.8 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    d:\tuneup utilities 2006\integrator.exe    337.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    d:\tuneup utilities 2006\keygen.exe    537.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    d:\tuneup utilities 2006\uninst.exe    116.8 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\Real\RealPlayer\realplay.exe    258.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\WinRAR\WinRAR.exe    447.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\WINISO53.EXE    816 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\Windows 流氓软件清理大师.exe    3.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\Winamp_5.08e_Pro_SC_Plus.exe    8.9 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\tu.exe    4.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\thunder5.0.3.86.exe    2.6 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\RealPlayer10-5GOLD_cn.exe    11.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\PrimoSetup.exe    10.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\MSJavaVM.exe    5.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\MP10Setup_skycn.exe    12.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\klcodec243f.exe    10 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\HelloNet_setup.exe    4.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\HA-TuneUp Utilities 2006-RCH.exe    6.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\HAP_WinRAR350B51Reg_LBJ.exe    1.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\DFX_7.2_for_Winamp_SC.exe    676.4 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\bsv2.8.0.065.EN.exe    4.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\BitComet_0.57.exe    1.7 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\6.exe    556.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\Ghost\GhostExp.exe    838.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\Ghost\Ghost32.exe    2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\Ghost\Ghost.exe    1.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\Winamp\Winamp.exe    1014.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\浩方对战平台\GameClient.exe    1.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\QQ\QQ.EXE    1.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\软件\FastAIT2007_2\2006-12-07\setup.exe    3.7 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\Ringz Studio\StormSet.exe    347.8 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\Ringz Studio\uninst6.04.08.exe    134.9 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\KuGoo3\KuGoo.exe    7.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe    4.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\Intel\Intel Application Accelerator\intelata.exe    606.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\DNA-drivers\Temporal_Tool\ATITemporalAASwitch.exe    198.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\DNA-drivers\ATITrayTools\atitray.exe    1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\Warcraft III\worldedit.exe    4.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\Warcraft III\World Editor.exe    114.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\Warcraft III\Warcraft III.exe    326.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\Warcraft III\War3.exe    1.6 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    F:\Warcraft III\Frozen Throne.exe    326.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\Dreamweaver MX官方中文版\Setup.exe    222.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\绿色工具\NvCoolFX2.2.exe    158.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\绿色工具\IEcq修复.exe    798 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\uninstall.exe    78.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\CS!\cstrike.exe    982.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\CS!\voice_tweak.exe    230.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\CS!\UNWISE.EXE    204.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\CS!\SierraUp.exe    514.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\CS!\opforup.exe    1.9 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\CS!\hltv.exe    346.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\CS\CS!\hlds.exe    134.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    E:\DIABLO II\BNUpdate.exe    246.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\WINDOWS\Logo1_.exe    58.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\Shredder.exe    141.9 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\K-Lite Codec Pack\unins000.exe    850.5 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\StartUpManager.exe    241.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\SystemControl.exe    128.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\Undelete.exe    217.3 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\SystemInformation.exe    480.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\SystemOptimizer.exe    440.1 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\UpdateWizard.exe    187.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\WinStylerThemeSvc.exe    173.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\WinStyler.exe    829.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\DiskCleaner.exe    280.0 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\MemOptimizer.exe    345.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\OneClickMaintenance.exe    102.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\PMLauncher.exe    67.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\ProcessManager.exe    269.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\RegistryCleaner.exe    404 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\RegistryDefrag.exe    163.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\RegistryDefragHelper.exe    67.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\RegistryEditor.exe    288.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\RescueCenter.exe    188.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\SilentUpdater.exe    131.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\TuneUp Utilities 2006\access.exe    82.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\WinPcap\npf_mgm.exe    106.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\WinPcap\daemon_mgm.exe    106.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\WinPcap\rpcapd.exe    134.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\Program Files\ATI Technologies\ATI Control Panel\atiprbxx.exe    178.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\X-Scan\xscan_gui.exe    1.8 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\X-Scan\Update.exe    856.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\WINDOWS\uninstall\rundl132.exe    58.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\BitComet\BitComet.exe    3.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    C:\program files\ati technologies\ati control panel\atiptaxx.exe    394.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\Ghost\Ghost32.exe    2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\Winamp\winampa.exe    91.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\Winamp\undfx70.exe    101.8 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc    D:\Thunder\Thunder.exe    98.2 KB
最后编辑2006-12-25 01:33:54
分享到:
gototop
 

[CODE]

2006-12-25,00:55:10

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
    <ATIModeChange><; Ati2mdxx.exe>  [ATI Technologies, Inc.]
    <ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [N/A]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <load><; C:\WINDOWS\uninstall\rundl132.exe>  [N/A]
    <ltnward><; C:\WINDOWS\system32\ltnward.exe>  [N/A]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <StormCodec_Helper><; "C:\Program Files\Ringz Studio\StormSet.exe" /S /opti>  [N/A]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]

==================================
启动文件夹
N/A

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Disabled]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Disabled]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[IdeBusDr / IdeBusDr][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
[Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
[kl1 / kl1][Running/Boot Start]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[p2pfilter / p2pfilter][Stopped/Manual Start]
  <\??\C:\Program Files\NetSoft\P2POver\p2pfilter.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
gototop
 

==================================
浏览器加载项
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Yahoo! Toolbar]
  {EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, N/A>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[VnetAnprIns Class]
  {74447F9C-5691-4A9A-8BE4-564092E40B03} <C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[ActiveMovieControl Object]
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VnetAnprIns Class]
  {74447F9C-5691-4A9A-8BE4-564092E40B03} <C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Yahoo! Toolbar]
  {EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, N/A>
[上传到QQ网络硬盘]
  <D:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
  <D:\KUGOO3\KuGoo3DownX.htm, N/A>
[添加到QQ自定义面板]
  <D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 492][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4109]
    [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 624][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 636][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 880][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 932][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1724][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1944][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 348][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [d:\TuneUp Utilities 2006\sdshelex.dll]  [TuneUp Software GmbH, 1.0.0.253]
    [d:\TuneUp Utilities 2006\rtl60.bpl]  [Borland Software Corporation, 6.0.6.241]
    [d:\TuneUp Utilities 2006\vcl60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 956][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 440][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 1004][C:\DOCUME~1\SaGa\LOCALS~1\Temp\sreng2.zip 的临时目录 1\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
[PID: 812][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA  错误: LoadLibraryA
RVA  错误: LoadLibraryExA
RVA  错误: LoadLibraryExW
RVA  错误: LoadLibraryW

==================================


[/CODE]
gototop
 

快点看看怎么会事
gototop
 

现在可以了,顶!之前删了一下EXE问题!
这个病毒真TMD叼!
谢谢楼上!
不知重启会不会在出现!
gototop
 

计算机重启后删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bs文件: C:\DOCUME~1\SaGa\LOCALS~1\Temp\rxzs.dll
这个怎样杀呀!!!!!!!!!!
顶重启还有!!!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT