12   1  /  2  页   跳转

电脑出现C:\WINDOWS\WIN.EXE是病毒吗?

电脑出现C:\WINDOWS\WIN.EXE是病毒吗?

用超级兔子在硬盘中找到以下可疑程序:
C:\WINDOWS\WIN.EXE,是病毒吗?
最后编辑2007-03-24 15:08:44
分享到:
gototop
 

怎么可以删掉啊?
gototop
 

我用诺顿和瑞星都查不出有病毒
gototop
 

可以讲具体点吗?
gototop
 

我下了icesword,接下来该怎么办啊?
gototop
 

怎么删?
gototop
 

是在icesword里查找文件吗?找不到啊?
gototop
 

在电脑里找的到,就在WINDOWS下,但是我用icesword打开文件,只显示WINDOWS下的文件夹,其他不是文件夹的内容都看不见的
gototop
 

[CODE]

2007-03-24,14:23:06

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [(Verified)Microsoft Corporation]
    <Super Rabbit IEPro><E:\资料\moon-tata\超级兔子\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <Apoint><C:\Program Files\Apoint\Apoint.exe>  [(Verified)Alps Electric Co., Ltd.]
    <Mouse Suite 98 Daemon><ICO.EXE>  [(Verified)Primax Electronics Ltd.]
    <ATIModeChange><; Ati2mdxx.exe>  [(Verified)ATI Technologies, Inc.]
    <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <HKSERV.EXE><C:\Program Files\Sony\HotKey Utility\HKserv.exe>  [Sony Corporation]
    <ezShieldProtector for Px><C:\WINDOWS\System32\ezSP_Px.exe>  [Easy Systems Japan Ltd.]
    <Drag'n Drop CD+DVD><C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp>  [N/A]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [(Verified)Symantec Corporation]
    <ccRegVfy><"C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe">  [(Verified)Symantec Corporation]
    <MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Corporation]
    <WangWang><"C:\Program Files\Alisoft\WangWang\WangWang.EXE">  [阿里软件(中国)有限公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
gototop
 

启动文件夹
[Microsoft Office]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>
[PowerPanel]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\PowerPanel.lnk --> C:\PROGRA~1\POWERP~1\Program\PcfMgr.exe [Phoenix Technologies Ltd.]><N>
[木马杀客2007]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\木马杀客2007.Lnk --> C:\PROGRA~1\木马杀客\mmsk.exe [N/A]><N>
[QQ游戏启动加速程序]
  <C:\Documents and Settings\allyapple\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> D:\新建文~1\新建文~1\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
[腾讯QQ]
  <C:\Documents and Settings\allyapple\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\新建文~1\新建文~1\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation Service / ccPwdSvc][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Norton AntiVirus 自动防护服务 / navapsvc][Running/Auto Start]
  <"C:\Program Files\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[ScriptBlocking Service / SBService][Stopped/Auto Start]
  <C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe><Symantec Corporation>
[Sony SPTI Service / SPTISRV][Stopped/Manual Start]
  <C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe><Sony Corporation>
[Windows Vista        / Windows Vista        ][Stopped/Auto Start]
  <C:\WINDOWS\win.exe><N/A>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>

==================================
驱动程序
[Alps Pointing-device Filter Driver / ApfiltrService][Running/Manual Start]
  <System32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[ati2mtag / ati2mtag][Running/Manual Start]
  <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Sony DMI Call service / DMICall][Running/System Start]
  <System32\DRIVERS\DMICall.sys><Sony Corporation>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
  <System32\DRIVERS\e100b325.sys><Intel Corporation>
[HSFHWICH / HSFHWICH][Running/Manual Start]
  <System32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP][Running/Manual Start]
  <System32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <System32\DRIVERS\mdmxsdk.sys><Conexant>
[NAVENG / NAVENG][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070321.018\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070321.018\NavEx15.Sys><Symantec Corporation>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\D:\新建文件夹\新建文件夹\QQ\npkycryp.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\PxHelp20.sys><Sonic Solutions>
[SAVRT / SAVRT][Running/Manual Start]
  <\??\C:\WINDOWS\System32\Drivers\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/Auto Start]
  <\??\C:\WINDOWS\System32\Drivers\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[Sony Notebook Control Device / SNC][Running/Manual Start]
  <System32\Drivers\SonyNC.sys><Sony Corporation>
[Sony Programmable I/O Control Device / SPI][Running/Manual Start]
  <System32\DRIVERS\SonyPI.sys><Sony Corporation>
[SymEvent / SymEvent][Running/Manual Start]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
  <\??\C:\WINDOWS\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/Auto Start]
  <\??\C:\WINDOWS\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[Intel(R) PRO/Wireless 7100 Adapter 驱动程序 / w70n51][Stopped/Manual Start]
  <System32\DRIVERS\w70n51.sys><Intel? Corporation>
[YAMAHA AC-XG Audio Device / WDM_YAMAHAAC97][Running/Manual Start]
  <system32\drivers\yacxgc.sys><YAMAHA CORPORATION>
[winachsf / winachsf][Running/Manual Start]
  <System32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\新建文件夹\新建文件夹\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT