瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】各位版主还有UFO.水树等高手,来帮帮忙,木马病毒现在瑞星查不出了

12   1  /  2  页   跳转

【求助】各位版主还有UFO.水树等高手,来帮帮忙,木马病毒现在瑞星查不出了

【求助】各位版主还有UFO.水树等高手,来帮帮忙,木马病毒现在瑞星查不出了

[url][/url][CODE]

2007-04-02,09:35:52

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <Super Rabbit Shutdown><C:\Nutz Software\Program Files\Super Rabbit\MagicSet\srshut.exe /LOAD>  [Super Rabbit Soft]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <Anti-Spy Tools><C:\Program Files\ast\AST.exe -min>  [DSW Lab]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>  [RealNetworks, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <CPushSetup><"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Common Files\CPUSH\cpush.dll">  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]

==================================
启动文件夹
N/A

==================================
服务
[Application Experience Lookup Services / AeLookupSvcs][Stopped/Auto Start]
  <C:\WINDOWS\system32\SVCH0ST.EXE -netsvcs><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Policy Agent Service V2.5 / paSvc][Running/Auto Start]
  <"C:\Program Files\AhnLab\APC2\Policy Agent\pasvc.exe"><AhnLab, Inc.>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
  <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>

==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HookCont / HookCont][Running/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\D:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[ofkere / ofkere][Stopped/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\ofkere.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ROCKEYNT / ROCKEYNT][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\Rockeynt.sys><FeiTian Tech Co.,Ltd>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
[Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
  <system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
  <system32\DRIVERS\wudfrd.sys><Microsoft Corporation>
最后编辑2007-04-04 14:07:59
分享到:
gototop
 

浏览器加载项
[Info cache]
  {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[实用搜索]
  {6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[超级兔子上网精灵]
  {FEDF637B-F631-4583-A210-33CC828D42DB} <C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL, N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\安装文件\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[超级兔子上网精灵]
  {FEDF637B-F631-4583-A210-33CC828D42DB} <C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL, N/A>
[实用搜索工具条2.0]
  {03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[实用搜索工具条2.0]
  {03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\WINDOWS\system32\dllcache\dhtmled.ocx, Microsoft Corporation>
[Info cache]
  {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[实用搜索]
  {6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD>
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, N/A>
[WebVGPlayer Class]
  {AA899B43-24BD-4B6B-BBD0-45557D8D11E0} <C:\PROGRA~1\VIEWGOOD\WEBPLA~1\VGPlayer.dll, >
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[CPasswordEditCtrl Object]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[超级兔子上网精灵]
  {FEDF637B-F631-4583-A210-33CC828D42DB} <C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL, N/A>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[Google 搜索(&G)]
  <res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\安装文件\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
gototop
 

正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\winlib .dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 548][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 560][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 716][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 764][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 860][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\smxbs.dll]  [Microsoft Corporation, 5.1.2600.0]
[PID: 908][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 952][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1280][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
[PID: 1364][C:\PROGRAM FILES\RISING\RAV\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [C:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1552][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.9134]
[PID: 1588][C:\Program Files\AhnLab\APC2\Policy Agent\pasvc.exe]  [AhnLab, Inc., 2.5.5.76]
    [C:\Program Files\AhnLab\APC2\Policy Agent\SLogW.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\SSync.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\IniRW.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\MSVCP60.dll]  [Microsoft Corporation, 6.00.8168.0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\TPool.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\MaCfgRw.dll]  [AhnLab, 2, 5, 5, 11]
    [C:\Program Files\AhnLab\APC2\Policy Agent\SBase64.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\PaNetApi.dll]  [AhnLab, Inc., 2, 5, 5, 90]
[PID: 1800][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
    [C:\Program Files\Unlocker\UnlockerCOM.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\qdshm.dll]  [, 1, 0, 101, 20]
    [D:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [c:\windows\system32\smxbs.dll]  [Microsoft Corporation, 5.1.2600.0]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9134]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9134]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [C:\Program Files\superutilbar\superutilbar.dll]  [www.shiyongsousuo.com, 2, 1, 8, 24]
[PID: 2000][c:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
    [c:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [c:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [c:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [c:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [c:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
[PID: 460][C:\Program Files\AhnLab\APC2\Policy Agent\paTray.exe]  [, 2, 5, 0, 10]
    [C:\Program Files\AhnLab\APC2\Policy Agent\AhnInst.dll]  [AhnLab, Inc., 6, 0, 0, 53]
    [C:\Program Files\AhnLab\APC2\Policy Agent\MaCfgRw.dll]  [AhnLab, 2, 5, 5, 11]
    [C:\Program Files\AhnLab\APC2\Policy Agent\IniRW.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\MSVCP60.dll]  [Microsoft Corporation, 6.00.8168.0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\SBase64.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\SLogW.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\SSync.dll]  [AhnLab, 2, 1, 0, 0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\AhnI18N.dll]  [AhnLab, Inc., 6, 0, 0, 18]
    [C:\Program Files\AhnLab\APC2\Policy Agent\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\AhnLab\APC2\Policy Agent\NLS\MTRY0804.nls]  [, 2, 0, 0, 2]
[PID: 1008][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1948][C:\Nutz Software\Program Files\Super Rabbit\MagicSet\srshut.exe]  [Super Rabbit Soft, 3.80]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
[PID: 880][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
[PID: 3112][C:\Program Files\TTPlayer\TTPlayer.exe]  [Alen Soft, 4, 6, 9, 0]
    [C:\Program Files\TTPlayer\ttpcomm.dll]  [N/A, ]
    [C:\Program Files\TTPlayer\ttpres.dll]  [Alen Soft, 4, 6, 9, 0]
    [C:\Program Files\TTPlayer\msdmo.dll]  [Microsoft Corporation, 6.03.01.0400]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\TTPlayer\AddIn\ttp_asf.dll]  [N/A, ]
    [C:\Program Files\TTPlayer\AddIn\ttp_aac.dll]  [N/A, ]
    [C:\Program Files\TTPlayer\AddIn\ttp_ac3dts.dll]  [N/A, ]
    [C:\Program Files\TTPlayer\wmadmod.dll]  [Microsoft Corporation, 10.00.00.3646]
    [C:\Program Files\TTPlayer\AddIn\ttp_lrcsh.dll]  [N/A, ]
[PID: 3440][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll]  [金泰丰(广州)科技有限公司, 2, 3, 0, 0]
    [C:\Program Files\superutilbar\superutilbar.dll]  [www.shiyongsousuo.com, 2, 1, 8, 24]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3059 (xpsp_sp2_gdr.070104-0050)]
    [C:\WINDOWS\system32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5076]
    [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
    [C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL]  [Microsoft Corporation, 9.0.5510.0]
[PID: 2396][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
[PID: 2324][C:\DOCUME~1\tang\LOCALS~1\Temp\Rar$EX06.360\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll]  [N/A, ]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.189382.cn
127.0.0.197725.com
127.0.0.143242.com
127.0.0.1gualeifafksajof.43242.com
127.0.0.1jiaofei123.140.tofor.com
127.0.0.1ben666888.www1.910idc.com
127.0.0.1pchorne.com
127.0.0.1www.ctv163.com
127.0.0.1www.aiaiso.com
127.0.0.1cool.47555.com
127.0.0.1guajfskajiw.43242.com
127.0.0.1www.3448.com
127.0.0.1pkdown.3322.org
127.0.0.1ddos2.sz45.com
127.0.0.1www.113678.com
127.0.0.1www.1861.sh
127.0.0.1www.burstnet.com
127.0.0.1www.commission-junction.com
127.0.0.1www.eads.com
127.0.0.1www.freestats.com
127.0.0.1www.imaginemedia.com
127.0.0.1www.netdirect.nl
127.0.0.1www.oneandonlynetwork.com
127.0.0.1www.targetshop.com
127.0.0.1www.teknosurf2.com
127.0.0.1www.teknosurf3.com
127.0.0.1www.valueclick.com
127.0.0.1www.websitefinancing.com
127.0.0.1www2.burstnet.com
127.0.0.1www4.trix.net
127.0.0.1www80.valueclick.com
127.0.0.1z.extreme-dm.com
127.0.0.1z0.extreme-dm.com
127.0.0.1z1.extreme-dm.com
127.0.0.1ads.rediff.com
127.0.0.1ads.indya.com
127.0.0.1ads.adflight.com
127.0.0.1ads.beguide.net
127.0.0.1ads.mediaturf.net
127.0.0.1ad1.adcept.net
127.0.0.1ad2.adcept.net
127.0.0.1ad3.adcept.net
127.0.0.1ads.fortunecity.com
127.0.0.1www.139cn.com
127.0.0.1www.7liao.com
127.0.0.1chat.51liao.net
127.0.0.1www.51liao.net
127.0.0.1www.7liao.net
127.0.0.1www.6see.com
127.0.0.1bliao.com
127.0.0.1www.bliao.com
127.0.0.1hao123.net
127.0.0.1www.hao123.net
127.0.0.1www.hao222.net
127.0.0.1www.hao222.com
127.0.0.1www.v111.com
127.0.0.1music.v111.com
127.0.0.1www.qq165.com
127.0.0.1www.xicu.com
127.0.0.1www.haodx.com
127.0.0.1www.haohz.com
127.0.0.1www.dj99.com
127.0.0.1www.dj99.net
127.0.0.1www.yqdj.com
127.0.0.1www.qq530.com
127.0.0.1www.tt67.com
127.0.0.1ad.t2t2.com
127.0.0.1www.yexr.com
127.0.0.1chat.9see.com
127.0.0.1www.ok816.com
127.0.0.1www.3399.net
127.0.0.1www.ads8.com
127.0.0.1www.5566.net
127.0.0.1www.t2t2.com
127.0.0.1popad.qq.com
127.0.0.1v.jsdownload.com
127.0.0.1www.linktoad.com
127.0.0.1club.homeway.com.cn
127.0.0.1sms1.ctn.com.cn
127.0.0.1sms2.ctn.com.cn
127.0.0.1sms3.ctn.com.cn
127.0.0.1www.331122.com
127.0.0.1mmpic.uni.cc
127.0.0.1www.love34.com
127.0.0.1www.free-movie.org
127.0.0.1www.skyhits.com
127.0.0.1www.rd18.com
127.0.0.1tadsweb.tencent.com
127.0.0.1www.vlike.com
127.0.0.1www.chinasee.net
127.0.0.1www.japansky.net
127.0.0.1www.225.com.cn
127.0.0.1ads.china.com
127.0.0.1www.yes521.com
127.0.0.1www.today6.com
127.0.0.1www.h2004.com
127.0.0.1www.movie4.com
127.0.0.1www.rm88.com
127.0.0.1www.qq300.com
127.0.0.1www.qq500.com
127.0.0.1www.av126.com
127.0.0.1www.kissmm.com
127.0.0.1www.cn808.net
127.0.0.1www.hao168.com
127.0.0.1www.mm91.com
127.0.0.1www.huole.com
127.0.0.1www.kan69.com
127.0.0.1ulinkdir.tom.com
127.0.0.1cpc.sohu.com
127.0.0.1images.sohu.com
127.0.0.1adv.pconline.com.cn
127.0.0.1goto.sohu.com
127.0.0.1images2.sohu.com
127.0.0.1www.sexy-books.com
127.0.0.1www.xxbooks.com
127.0.0.1www.18it.com
127.0.0.1www.cnxxx.com
127.0.0.1www.18-girl.net
127.0.0.1ad.tom.com
gototop
 

127.0.0.1ad4.sina.com.cn
127.0.0.1sina.allyes.com
127.0.0.1adtaobao.allyes.com
127.0.0.1smarttrade.allyes.com
127.0.0.1tom.allyes.com
127.0.0.1szwindow.allyes.com
127.0.0.1eachnetmember.allyes.com
127.0.0.1iplus.allyes.com
127.0.0.1sinatest.allyes.com
127.0.0.1casting9.allyes.com
127.0.0.1yinsha.allyes.com
127.0.0.1stockstar.allyes.com
127.0.0.1www.001x.com
127.0.0.1www.hksexweb.com
127.0.0.1www.99adultx.com
127.0.0.1www2.xfreehosting.com
127.0.0.1www1.xfreehosting.com
127.0.0.1www.w555.net
127.0.0.1www.excitecity.com
127.0.0.1www.0xing.com
127.0.0.1sba.3322.net
127.0.0.1www.zgxl.net
127.0.0.1www.qqpic.com
127.0.0.1webspacecn.com
127.0.0.1www.yeapple.com
127.0.0.1manage.link8.com
127.0.0.1www.web888.org
127.0.0.1www.432.cn
127.0.0.1www.kan123.com
127.0.0.1www.3tom.com
127.0.0.1www.sotop.com
127.0.0.1www3.7789.com
127.0.0.1www.66036.com
127.0.0.1www1.66036.com
127.0.0.1www2.66036.com
127.0.0.1www3.66036.com
127.0.0.1www4.66036.com
127.0.0.1www5.66036.com
127.0.0.1www6.66036.com
127.0.0.1www7.66036.com
127.0.0.1www8.66036.com
127.0.0.1www9.66036.com
127.0.0.1www10.66036.com
127.0.0.1tj4.7789.com
127.0.0.1tj5.7789.com
127.0.0.1tj6.7789.com
127.0.0.1tj7.7789.com
127.0.0.1www.7789.com
127.0.0.1count.zhao123.com
127.0.0.1count1.zhao123.com
127.0.0.1count2.zhao123.com
127.0.0.1count3.zhao123.com
127.0.0.1count4.zhaocount.com
127.0.0.1count5.zhaocount.com
127.0.0.1count6.zhaocount.com
127.0.0.1count7.zhaocount.com
127.0.0.1count8.zhaocount.com
127.0.0.1count9.zhaocount.com
127.0.0.1count10.zhaocount.com
127.0.0.1count11.zhaocount.com
127.0.0.1tj1.mytongji.com
127.0.0.1count1.99count.com
127.0.0.1www.99count.com
127.0.0.1bar.baidu.com
127.0.0.1www2.7789.com
127.0.0.1www.guang.org
127.0.0.1www.dlmovie.com
127.0.0.1www.91look.com
127.0.0.1www.kan51.com
127.0.0.1www.mewo.com
127.0.0.1coolsite21.com
127.0.0.1www.t3j4.com
127.0.0.1www.yun8.com
127.0.0.1film.yun8.com
127.0.0.1www.wo123.com
127.0.0.1www.da123.com
127.0.0.1www.1ya.cn
127.0.0.1www.sleazydream.com
127.0.0.1www.easypic2.com
127.0.0.1serv.sexushost.com
127.0.0.1www.xfreehosting.com
127.0.0.1www.888txt.com
127.0.0.1asiafriendfinder.com
127.0.0.1www3.cool168.com
127.0.0.1www2.cool168.com
127.0.0.1www1.cool168.com
127.0.0.1www.happy8.cn
127.0.0.1www.topsex2k.com
127.0.0.1topxxx.sexushost.com
127.0.0.1www.cool168.com
127.0.0.1www.s6.cn
127.0.0.1popme.163.com
127.0.0.1adclient.163.com
127.0.0.1fadama.com
127.0.0.1www.66vv.com
127.0.0.1www.qqee.com
127.0.0.1www.sohu123.com
127.0.0.1www.xgmm.com
127.0.0.1www.7t7t.com
127.0.0.1www.cnimg.com
127.0.0.1cdn2.cnnic.cn
127.0.0.1cool.vv66.com
127.0.0.1www.vv66.com
127.0.0.1www.freepicturepage.com
127.0.0.1www.snasty.com
127.0.0.1www.yourcage.com
127.0.0.1www.shagadelic.com
127.0.0.1hualiao.net
127.0.0.1www.qq163.com
127.0.0.1www.qq163.net
127.0.0.1www.superdown.com
127.0.0.1web.114.com.cn
127.0.0.1www.114.com.cn
127.0.0.1www.91f.cn
127.0.0.1wwww.tthao.com
127.0.0.1www.91f.org
127.0.0.1www.v23.com
127.0.0.1auto.search.msn.com
127.0.0.1x2.51link.com
127.0.0.1www.dosboy.com
127.0.0.1x1.51link.com
127.0.0.1www.textlink.cn
127.0.0.1stat.textclick.com
127.0.0.1www.easyhere.com
127.0.0.1www.xxx168.com
127.0.0.1ally.263.net
127.0.0.1www.hualiao.net
127.0.0.1www.xchina.com
127.0.0.1www.sex.com
127.0.0.1www.3xcn.com
127.0.0.1www.20girl.com
127.0.0.1www.x365x.com
127.0.0.1chat.263.net
127.0.0.1chat.yinsha.com
127.0.0.1chat.tom.com
127.0.0.1chat.xilu.com
127.0.0.1www.aliao.com
127.0.0.1chat.163.com
127.0.0.1www.haoliao.com
127.0.0.1www.liaoliao.com
127.0.0.1www.haoliao.net
127.0.0.1www.haoliao.cn
127.0.0.1www.qqliao.com
127.0.0.1www.qliao.com
127.0.0.1www.loveliao.com
127.0.0.1www.mmliao.com
127.0.0.1chat.qq.com
127.0.0.1vchat.xaonline.com
127.0.0.1www.loveliao.net
127.0.0.1www.sogua.com
127.0.0.1www.99music.net
127.0.0.1www.yzskdj.com
127.0.0.1music.feifa.com
127.0.0.1www.aisex.com
127.0.0.1www.movie-down.com
127.0.0.1www2.movie-down.com
127.0.0.1www.tt90.com
127.0.0.1www.tt78.com
127.0.0.1www.tiankong.net
127.0.0.1www.qqchat.cn
127.0.0.1www.9see.com
127.0.0.1www.woliao.net
127.0.0.1www.woliao.com
127.0.0.1www.kuro.com.cn
127.0.0.1www.wangzhiku.com
127.0.0.1hothack.home.chinaren.com
127.0.0.1www.777888.com
127.0.0.1www.5dsoft.com
127.0.0.1www.wokoo.net
127.0.0.1movie.sx.zj.cn
127.0.0.1xyxy68.8u8.net
127.0.0.1www.youmiss.com
127.0.0.1www.cctv8.net
127.0.0.1www.kuliao.com
127.0.0.1www.yyqy.com
127.0.0.1www.sunvod.com
127.0.0.1www.t168.com
127.0.0.1www.coolcdrom.com
127.0.0.1www.zhengdian.com
127.0.0.1girlchinese.com
127.0.0.1www.girl008.com
127.0.0.1xajh.15888.net
127.0.0.1www.51bug.com
127.0.0.1www.wplune.com
127.0.0.1www.777888.net
127.0.0.1pollen.my001.net
127.0.0.1www.yule21.com
127.0.0.1www.fish3000.com
127.0.0.1www.666e.com
127.0.0.1qm.8ok.com
127.0.0.1www.guosir.ccoo.com
127.0.0.1www.163mm.com
127.0.0.1www.cnooo.com
127.0.0.1www.es158.com
127.0.0.1www.aisa-girl.net
127.0.0.1www.boliwu.com
127.0.0.1www.89005.com
127.0.0.1www.cctv1.net
127.0.0.1www.play.cn.gs
127.0.0.1newyouth.3322.net
127.0.0.1chinabdkx.363.net
127.0.0.1www.zknew.com
127.0.0.1www.dhchao.com
127.0.0.1www.top666.net
127.0.0.1www.amoisonic.com
127.0.0.1www.markguide.com
127.0.0.1www.xyxc.ccoo.com
127.0.0.1www.flyingwalk.com
127.0.0.1www.yezine.net
127.0.0.1www.mmgirls.com
127.0.0.1www.wa***.net
127.0.0.1www.net5w.com
127.0.0.1www.fbstu.com
127.0.0.1www.qlwl.com
127.0.0.1www.yibinren.com
127.0.0.1www.yinshang.com
127.0.0.1www.ncunet.com
127.0.0.1www.555666.net
127.0.0.1www.fm1058.cc
127.0.0.1meim.y365.com
127.0.0.1www.qq520.net
127.0.0.1jjkafei.longcity.net
127.0.0.1chow.yesky.net
127.0.0.1oicq.hk.st
127.0.0.1www.my288.com
127.0.0.1www.laws-online.net
127.0.0.1www.hj168.net
127.0.0.116888.6to23.com
127.0.0.1www.ezhgc.com
127.0.0.1www.eastedu.com.cn
127.0.0.1www.435000.com
127.0.0.1sdik.8ok.net
127.0.0.1feiying.coolwww.net
127.0.0.1zhongxuesheng.myrice.com
127.0.0.1www.yes9999.com   
127.0.0.1www.nnptt.com
127.0.0.1vod.hengshui.com
127.0.0.1tv.megajoy.com
127.0.0.1www.h444.net
127.0.0.1update.myxq.com
127.0.0.1www.qq168.net  
127.0.0.1www.777888.com  
127.0.0.1www.5dsoft.com  
127.0.0.1movie.sx.zj.cn   
127.0.0.1www.yeapple.com  
127.0.0.1winzheng.126.com
127.0.0.1www.boliwo.com
127.0.0.1www.pk.com
127.0.0.1www.unionsky.cn
127.0.0.1www.allyes.com
127.0.0.1www.xxx.com
127.0.0.1204.177.92.68
127.0.0.1www.fassia.net        
127.0.0.1www.jinpin.net        
127.0.0.1www.happy666.net
127.0.0.1www.myxq.com
127.0.0.1dvd.qq92.com
127.0.0.1www.16yi.com
127.0.0.1www.ye77.com
127.0.0.1www.7sese.com
127.0.0.1www.1yin.net
127.0.0.1www.77ttt.com
127.0.0.1www.7mao.com
127.0.0.1www.mydj2005.com
127.0.0.1www.vv78.com
127.0.0.1www.v119.com
127.0.0.1100.332233.com
127.0.0.1www.cashbackbuddy.com
127.0.0.1www.10uu.com
127.0.0.1fly950.nease.net

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll)
RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll)
RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll)
RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: C:\Nutz Software\Program Files\Super Rabbit\MagicSet\SRshutdown.dll)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

自己顶,只有点击,没有回复。。。。。。。
gototop
 

郁闷!机子反应越来越慢了,老是卡卡,鼠标就不动了。。。。高手帮帮忙把。。。
gototop
 

呵呵,真是同病相怜。。。。。。可恶的木马病毒,每次都要重装系统,烦死了!
gototop
 

【回复“sophiahuier”的帖子】偶是学生,比起你来,还好点,卡住了,就上网不爽,等一等,相信会有高手来帮忙的,高手也有高手的工作,何况坛上这么多求助者,在等等,,,,,要是自己会看日志就好了,不但自己解决了,还可以帮助别人。。。。。
gototop
 

郁闷中。。。。。。。。。。。。。
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT