1   1  /  1  页   跳转

帮帮忙,中病毒了(附日志)

帮帮忙,中病毒了(附日志)

如题:麻烦大家帮帮忙,谢谢各位了


2007-04-25,16:49:39

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS.0\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
    <Death.exe><C:\WINDOWS.0\system32\Death.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <BigDogPath><; C:\WINDOWS.0\VM_STI.EXE VIMICRO USB PC Camera>  [N/A]
    <runeip><; C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><; "D:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <IMJPMIG8.1><; C:\WINDOWS.0\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS.0\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS.0\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <hxgame-update><; C:\Program Files\hxupdate\hxgame-update.exe>  [N/A]
    <winform><C:\WINDOWS.0\winform.exe>  [N/A]
    <mppds><C:\WINDOWS.0\mppds.exe>  [N/A]
    <System><C:\Program Files\Common Files\System\Updaterun.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS.0\system32\userinit.exe,rundll32.exe C:\WINDOWS.0\System32\winsys16_070314.dll start>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{5D06580A-08EB-4DD0-8425-DDBB5198B30C}><C:\Program Files\Common Files\Microsoft Shared\MSInfo\IEINFO5.sys>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS.0\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[P4P Service / P4P Service][Running/Auto Start]
  <C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[System Administrator / Popular][Running/Auto Start]
  <C:\WINDOWS.0\System32\svchost.exe -k netsvcs-->C:\WINDOWS.0\system32\noycn.dll><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[System Event Log Service / SystemLog][Stopped/Auto Start]
  <C:\WINDOWS.0\system32\shellext\services.exe><N/A>
[Intranet Messenger / WalALET][Running/Auto Start]
  <C:\WINDOWS.0\SYSTEM32\RUNDLL2KXP.EXE C:\WINDOWS.0\SYSTEM32\WBEM\ZHDDT.DLL,Export 1087><Microsoft Corporation>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[acpidisk / acpidisk][Running/Auto Start]
  <\??\C:\WINDOWS.0\System32\drivers\acpidisk.sys><N/A>
[AFD 网络支持环境 / AFD][Running/System Start]
  <\SystemRoot\System32\drivers\afd.sys><Microsoft Corporation>
[Intel AGP Bus Filter / agp440][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\agp440.sys><Microsoft Corporation>
[RAS Asynchronous Media Driver / AsyncMac][Stopped/Manual Start]
  <System32\DRIVERS\asyncmac.sys><Microsoft Corporation>
[标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\atapi.sys><Microsoft Corporation>
[ATM ARP Client Protocol / Atmarpc][Stopped/Manual Start]
  <System32\DRIVERS\atmarpc.sys><Microsoft Corporation>
[音频存根驱动程序 / audstub][Running/Manual Start]
  <System32\DRIVERS\audstub.sys><Microsoft Corporation>
[BaseTDI / BaseTDI][Running/Auto Start]
  <\??\C:\WINDOWS.0\System32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[cakafo3 / cakafo38][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cakafo38.sys><Microsoft Corporation>
[Closed Caption Decoder / CCDECODE][Stopped/Manual Start]
  <System32\DRIVERS\CCDECODE.sys><Microsoft Corporation>
[CD-ROM Driver / Cdrom][Running/System Start]
  <System32\DRIVERS\cdrom.sys><Microsoft Corporation>
[磁盘驱动器 / Disk][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\disk.sys><Microsoft Corporation>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><Microsoft Corp., Veritas Software>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><Microsoft Corp., Veritas Software>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys><Microsoft Corp., Veritas Software.>
[Microsoft Kernel DLS Syntheiszer / DMusic][Stopped/Manual Start]
  <system32\drivers\DMusic.sys><Microsoft Corporation>
[Microsoft Kernel DRM Audio Descrambler / drmkaud][Stopped/Manual Start]
  <system32\drivers\drmkaud.sys><Microsoft Corporation>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\ExpScan.sys><>
[Floppy Disk Controller Driver / Fdc][Running/Manual Start]
  <System32\DRIVERS\fdc.sys><Microsoft Corporation>
[软盘驱动程序 / Flpydisk][Running/Manual Start]
  <System32\DRIVERS\flpydisk.sys><Microsoft Corporation>
[FltMgr / FltMgr][Running/Boot Start]
  <\SystemRoot\system32\drivers\fltmgr.sys><Microsoft Corporation>
[FsVga / FsVga][Running/System Start]
  <System32\DRIVERS\fsvga.sys><Microsoft Corporation>
[Volume Manager Driver / Ftdisk][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\ftdisk.sys><Microsoft Corporation>
[Game Port Enumerator / gameenum][Running/Manual Start]
  <System32\DRIVERS\gameenum.sys><Microsoft Corporation>
[Generic Packet Classifier / Gpc][Running/Manual Start]
  <System32\DRIVERS\msgpc.sys><Microsoft Corporation>
[hasx / hasxl][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\hasxl.sys><N/A>
[HookCont / HookCont][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HTTP / HTTP][Stopped/Manual Start]
  <System32\Drivers\HTTP.sys><N/A>
[i8042 键盘和 PS/2 鼠标端口驱动程序 / i8042prt][Running/System Start]
  <System32\DRIVERS\i8042prt.sys><Microsoft Corporation>
[IntelIde / IntelIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\intelide.sys><Microsoft Corporation>
[IPv6 Windows Firewall Driver / ip6fw][Stopped/Manual Start]
  <system32\drivers\ip6fw.sys><Microsoft Corporation>
[IP Traffic Filter Driver / IpFilterDriver][Stopped/Manual Start]
  <System32\DRIVERS\ipfltdrv.sys><Microsoft Corporation>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <System32\DRIVERS\ipinip.sys><Microsoft Corporation>
[IP Network Address Translator / IpNat][Running/Manual Start]
  <System32\DRIVERS\ipnat.sys><Microsoft Corporation>
[IPSEC driver / IPSec][Running/System Start]
  <System32\DRIVERS\ipsec.sys><Microsoft Corporation>
[IR Enumerator Service / IRENUM][Stopped/Manual Start]
  <System32\DRIVERS\irenum.sys><Microsoft Corporation>
[PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\isapnp.sys><Microsoft Corporation>
[Keyboard Class Driver / Kbdclass][Running/System Start]
  <System32\DRIVERS\kbdclass.sys><Microsoft Corporation>
[Microsoft Kernel Wave Audio Mixer / kmixer][Running/Manual Start]
  <system32\drivers\kmixer.sys><Microsoft Corporation>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS.0\System32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
最后编辑2007-04-26 08:06:40
分享到:
gototop
 

[Mouse Class Driver / Mouclass][Running/System Start]
  <System32\DRIVERS\mouclass.sys><Microsoft Corporation>
[WebDav Client Redirector / MRxDAV][Running/Manual Start]
  <System32\DRIVERS\mrxdav.sys><Microsoft Corporation>
[MRxSmb / MRxSmb][Stopped/System Start]
  <System32\DRIVERS\mrxsmb.sys><N/A>
[Microsoft Streaming Service Proxy / MSKSSRV][Stopped/Manual Start]
  <system32\drivers\MSKSSRV.sys><Microsoft Corporation>
[Microsoft Streaming Clock Proxy / MSPCLOCK][Stopped/Manual Start]
  <system32\drivers\MSPCLOCK.sys><Microsoft Corporation>
[Microsoft Streaming Quality Manager Proxy / MSPQM][Stopped/Manual Start]
  <system32\drivers\MSPQM.sys><Microsoft Corporation>
[msqmx / msqmx][Running/Boot Start]
  <\SystemRoot\system32\drivers\msqmx.sys><N/A>
[Microsoft System Management BIOS Driver / mssmbios][Running/Manual Start]
  <System32\DRIVERS\mssmbios.sys><Microsoft Corporation>
[Microsoft Streaming Tee/Sink-to-Sink Converter / MSTEE][Stopped/Manual Start]
  <system32\drivers\MSTEE.sys><Microsoft Corporation>
[Microsoft MPU-401 MIDI UART Driver / ms_mpu401][Running/Manual Start]
  <system32\drivers\msmpu401.sys><Microsoft Corporation>
[NABTS/FEC VBI Codec / NABTSFEC][Stopped/Manual Start]
  <System32\DRIVERS\NABTSFEC.sys><Microsoft Corporation>
[Microsoft TV/Video Connection / NdisIP][Stopped/Manual Start]
  <System32\DRIVERS\NdisIP.sys><Microsoft Corporation>
[Remote Access NDIS TAPI Driver / NdisTapi][Running/Manual Start]
  <System32\DRIVERS\ndistapi.sys><Microsoft Corporation>
[NDIS 用户模式 I/O 协议 / Ndisuio][Running/Manual Start]
  <System32\DRIVERS\ndisuio.sys><Microsoft Corporation>
[Remote Access NDIS WAN Driver / NdisWan][Running/Manual Start]
  <System32\DRIVERS\ndiswan.sys><Microsoft Corporation>
[NetBIOS Interface / NetBIOS][Running/System Start]
  <System32\DRIVERS\netbios.sys><Microsoft Corporation>
[NetBios over Tcpip / NetBT][Running/System Start]
  <System32\DRIVERS\netbt.sys><Microsoft Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nv4 / nv4][Stopped/Manual Start]
  <System32\DRIVERS\nv4.sys><NVIDIA Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
  <System32\DRIVERS\nwlnkflt.sys><Microsoft Corporation>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
  <System32\DRIVERS\nwlnkfwd.sys><Microsoft Corporation>
[oheisp5 / oheisp55][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\oheisp55.sys><N/A>
[oomkqq9 / oomkqq90][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\oomkqq90.sys><N/A>
[Parallel port driver / Parport][Running/Manual Start]
  <System32\DRIVERS\parport.sys><Microsoft Corporation>
[PCI Bus Driver / PCI][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\pci.sys><Microsoft Corporation>
[WAN Miniport (PPTP) / PptpMiniport][Running/Manual Start]
  <System32\DRIVERS\raspptp.sys><Microsoft Corporation>
[处理器驱动程序 / Processor][Running/System Start]
  <System32\DRIVERS\processr.sys><Microsoft Corporation>
[QoS Packet Scheduler / PSched][Running/Manual Start]
  <System32\DRIVERS\psched.sys><Microsoft Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Remote Access Auto Connection Driver / RasAcd][Running/System Start]
  <System32\DRIVERS\rasacd.sys><Microsoft Corporation>
[WAN Miniport (L2TP) / Rasl2tp][Running/Manual Start]
  <System32\DRIVERS\rasl2tp.sys><Microsoft Corporation>
[远程访问 PPPOE 驱动程序 / RasPppoe][Running/Manual Start]
  <System32\DRIVERS\raspppoe.sys><Microsoft Corporation>
[Direct Parallel / Raspti][Running/Manual Start]
  <System32\DRIVERS\raspti.sys><Microsoft Corporation>
[Rdbss / Rdbss][Stopped/System Start]
  <System32\DRIVERS\rdbss.sys><N/A>
[RDPCDD / RDPCDD][Running/System Start]
  <System32\DRIVERS\RDPCDD.sys><Microsoft Corporation>
[Terminal Server Device Redirector Driver / rdpdr][Running/Manual Start]
  <System32\DRIVERS\rdpdr.sys><Microsoft Corporation>
[Digital CD Audio Playback Filter Driver / redbook][Running/System Start]
  <System32\DRIVERS\redbook.sys><Microsoft Corporation>
[rsdt / rsdt][Running/Auto Start]
  <\??\C:\WINDOWS.0\System32\drivers\rsdt.sys><>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[Serenum Filter Driver / serenum][Running/Manual Start]
  <System32\DRIVERS\serenum.sys><Microsoft Corporation>
[Serial port driver / Serial][Running/System Start]
  <System32\DRIVERS\serial.sys><Microsoft Corporation>
[skpvjn5 / skpvjn50][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\skpvjn50.sys><N/A>
[BDA Slip De-Framer / SLIP][Stopped/Manual Start]
  <System32\DRIVERS\SLIP.sys><Microsoft Corporation>
[Microsoft Kernel Audio Splitter / splitter][Stopped/Manual Start]
  <system32\drivers\splitter.sys><Microsoft Corporation>
[System Restore Filter Driver / sr][Stopped/Disabled]
  <\SystemRoot\System32\DRIVERS\sr.sys><Microsoft Corporation>
[Srv / Srv][Stopped/Manual Start]
  <System32\DRIVERS\srv.sys><Microsoft Corporation>
[BDA IPSink / streamip][Stopped/Manual Start]
  <System32\DRIVERS\StreamIP.sys><Microsoft Corporation>
[Software Bus Driver / swenum][Running/Manual Start]
  <System32\DRIVERS\swenum.sys><Microsoft Corporation>
[Microsoft Kernel GS Wavetable Synthesizer / swmidi][Stopped/Manual Start]
  <system32\drivers\swmidi.sys><Microsoft Corporation>
[Microsoft Kernel System Audio Device / sysaudio][Running/Manual Start]
  <system32\drivers\sysaudio.sys><Microsoft Corporation>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <System32\DRIVERS\tcpip.sys><Microsoft Corporation>
[Terminal Device Driver / TermDD][Running/System Start]
  <System32\DRIVERS\termdd.sys><Microsoft Corporation>
[Microcode Update Driver / Update][Running/Manual Start]
  <System32\DRIVERS\update.sys><Microsoft Corporation>
[USB2 Enabled Hub / usbhub][Running/Manual Start]
  <System32\DRIVERS\usbhub.sys><Microsoft Corporation>
[USB 大容量存储设备 / USBSTOR][Stopped/Manual Start]
  <System32\DRIVERS\USBSTOR.SYS><Microsoft Corporation>
[Microsoft USB Universal Host Controller Miniport Driver / usbuhci][Running/Manual Start]
  <System32\DRIVERS\usbuhci.sys><Microsoft Corporation>
[VGA 显示控制器。 / VgaSave][Running/System Start]
  <\SystemRoot\System32\drivers\vga.sys><Microsoft Corporation>
[Remote Access IP ARP Driver / Wanarp][Running/Manual Start]
  <System32\DRIVERS\wanarp.sys><Microsoft Corporation>
[Microsoft WINMM WDM Audio Compatibility Driver / wdmaud][Running/Manual Start]
  <system32\drivers\wdmaud.sys><Microsoft Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[xmvjau4 / xmvjau42][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\xmvjau42.sys><N/A>
[VIMICRO USB PC Camera / ZSMC301b][Running/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
gototop
 

浏览器加载项
[Thunder Browser Helper]
  {0CB66BA7-5E1F-4963-93D1-E1D6B78FE9A2} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
[网页搜索]
  {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} <C:\WINDOWS.0\system32\nethelp.dll, Microsoft Corporation>
[CAdLogic Object]
  {11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush0.dll, N/A>
[Info cache]
  {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[]
  {47CFDDF9-6FBD-4C06-8752-24FEFBA10D51} <C:\WINDOWS.0\system32\msiebho.dll, N/A>
[DLMgr Class]
  {4FA955E8-C73C-4D72-BDCC-EA12227B45D9} <D:\Program Files\Dianlei\Plugins\DLManager.dll, 电雷超级下载>
[实用搜索]
  {6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[网页搜索]
  {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} <C:\WINDOWS.0\system32\sporder.dll, Microsoft Corporation>
[电雷超级下载]
  {A6A84943-17AB-4363-A518-8D750FDF57C3} <"D:\Program Files\Dianlei\dianlei.exe", N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ07\QQ.EXE, TENCENT>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[实用搜索工具条2.0]
  {03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[网页搜索]
  {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} <C:\WINDOWS.0\system32\sporder.dll, Microsoft Corporation>
[MMCPlayer Class]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS.0\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS.0\System32\wuweb.dll, Microsoft Corporation>
[AYDownLoad Control]
  {71563D23-91B6-4B96-8966-B5642A1809E3} <C:\WINDOWS.0\DOWNLO~1\AYDOWN~1.OCX, >
[AYUpLoad Control]
  {7FD1EEC1-796A-4658-B1AB-41989D65161A} <C:\WINDOWS.0\DOWNLO~1\AYUpLoad.ocx, yanyan>
[Tencent Safety Online Base Module]
  {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} <C:\WINDOWS.0\DOWNLO~1\TSOBase.ocx, Tencent Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS.0\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[实用搜索工具条2.0]
  {03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[Thunder Browser Helper]
  {0CB66BA7-5E1F-4963-93D1-E1D6B78FE9A2} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
[网页搜索]
  {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} <C:\WINDOWS.0\system32\nethelp.dll, Microsoft Corporation>
[CAdLogic Object]
  {11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush0.dll, N/A>
[Info cache]
  {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[]
  {47CFDDF9-6FBD-4C06-8752-24FEFBA10D51} <C:\WINDOWS.0\system32\msiebho.dll, N/A>
[DLMgr Class]
  {4FA955E8-C73C-4D72-BDCC-EA12227B45D9} <D:\Program Files\Dianlei\Plugins\DLManager.dll, 电雷超级下载>
[实用搜索]
  {6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Tencent Safety Online Base Module]
  {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} <C:\WINDOWS.0\DOWNLO~1\TSOBase.ocx, Tencent Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS.0\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS.0\DOWNLO~1\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[CPasswordEditCtrl Object]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS.0\System32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[&Net Search]
  <res://C:\WINDOWS.0\system32\sporder.dll/MENUSEARCH.HTM, N/A>
[&使用电雷下载]
  <D:\Program Files\Dianlei\geturl.htm, N/A>
[&使用迅雷下载]
  <D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ07\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ07\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ07\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ07\SendMMS.htm, N/A>

==================================
gototop
 

正在运行的进程
[PID: 424][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 484][\??\C:\WINDOWS.0\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][\??\C:\WINDOWS.0\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS.0\system32\winlib .dll]  [N/A, N/A]
[PID: 552][C:\WINDOWS.0\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564][C:\WINDOWS.0\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][C:\WINDOWS.0\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 768][C:\WINDOWS.0\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 836][D:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 852][C:\WINDOWS.0\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][C:\WINDOWS.0\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1000][C:\WINDOWS.0\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1016][D:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 39]
    [D:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [D:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Program Files\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [D:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [D:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [D:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [D:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [D:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [D:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [D:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [D:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [D:\Program Files\Rising\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [D:\Program Files\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [D:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [D:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [D:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [D:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [D:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 34]
    [D:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
    [D:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [D:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [D:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [D:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
    [D:\Program Files\Rising\Rav\RsVM.dll]  [N/A, 19, 0, 0, 13]
    [D:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [D:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[PID: 1352][C:\WINDOWS.0\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\Microsoft Shared\MSInfo\IEINFO5.sys]  [N/A, N/A]
    [C:\WINDOWS.0\system32\wsxfn.dll]  [N/A, N/A]
    [C:\WINDOWS.0\system32\mppds.dll]  [N/A, N/A]
    [C:\WINDOWS.0\system32\winform.dll]  [N/A, N/A]
    [C:\WINDOWS.0\system32\cakafo38.dll]  [, 1, 1, 1, 1010]
    [C:\WINDOWS.0\system32\mprss.dll]  [N/A, N/A]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
    [C:\Program Files\superutilbar\superutilbar.dll]  [www.shiyongsousuo.com, 2, 1, 8, 24]
[PID: 1412][D:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [D:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1716][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe]  [Sohu.com Inc., 2, 0, 0, 31]
    [C:\Program Files\Sogou PXP\vodsvr.dll]  [Sohu.com Inc., 2, 4, 0, 5]
    [C:\Program Files\Sogou PXP\pxpnet.dll]  [Sohu.com Inc., 1, 0, 0, 9]
    [C:\Program Files\Sogou PXP\p2pclient.dll]  [Sohu.com Inc., 2, 9, 1, 6]
[PID: 1780][C:\WINDOWS.0\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 144][C:\Program Files\Common Files\System\Updaterun.exe]  [N/A, N/A]
[PID: 224][C:\WINDOWS.0\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS.0\system32\cakafo38.dll]  [, 1, 1, 1, 1010]
[PID: 240][C:\WINDOWS.0\System32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 284][C:\WINDOWS.0\system32\Death.exe]  [N/A, N/A]
[PID: 288][C:\WINDOWS.0\SYSTEM32\RUNDLL2KXP.EXE]  [Microsoft Corporation, 5.00.2134.1]
[PID: 628][C:\WINDOWS.0\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS.0\system32\cakafo38.dll]  [, 1, 1, 1, 1010]
[PID: 1600][C:\WINDOWS.0\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS.0\system32\cakafo38.dll]  [, 1, 1, 1, 1010]
[PID: 280][C:\WINDOWS.0\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2340][C:\WINDOWS.0\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 2612][C:\WINDOWS.0\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\WINDOWS.0\system32\cakafo38.dll]  [, 1, 1, 1, 1010]
[PID: 2808][C:\WINDOWS.0\system32\wpabaln.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS.0\system32\cakafo38.dll]  [, 1, 1, 1, 1010]
[PID: 3928][D:\Program Files\应用软件夹\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINDOWS.0\system32\cakafo38.dll]  [, 1, 1, 1, 1010]
    [C:\WINDOWS.0\system32\winform.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS.0\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A
gototop
 

还有就是这个网址(http://www.yx380.com/)删了就会在桌面上自动建一个快捷方式的,怎么办啊?
http://www.6781.com/index.htm网址总是自动设为主页,谢谢各位了!!!
gototop
 

瑞星文件监控  不停的跳出对话框分别显示:
文件路径:C:\WINDOWS.0\system32\winform.dll 
病毒名称:Trojan.PSW.OnlineGames.acy;
文件路径:C:\WINDOWS.0\system32\mppds.dll
病毒名称: Trojan.PSW.Wowar.aeg;
文件路径:C:\WINDOWS.0\system32\nethelp.dll
病毒名称:Trojan.DL.Mnless.qc;
文件路径:C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\PCTools\pctools.dll   
病毒名称:Trojan.DL.MNLess.im 
求高手啊??????????
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT