瑞星卡卡安全论坛
Jasonself - 2006-7-4 1:57:00
我把中毒情况也交代下,先是玩伊苏6,玩不下去了去网上找攻略,找到http://www.atgame.cn/danji-youxi-gonglue-miji/yongyuandeyisu6/上的伊苏6攻略就没关网页继续玩了,玩着就觉得很卡,切出来发现一直在不停有东西跳出来自动安装,我赶紧把网线拔掉查毒,再用木马克星查木马,瑞星查不出病毒源文件,每次我点IE的时候瑞星会报警提示新建的C:\WINDOWS\SYSTEM32\inituser.exe.tmp为Trojan.DL.Agent.alu病毒。我把日志传一下。望高手帮忙解决下,我在网上找了半天没发现这病毒的解决办法。不知道这个病毒是否和那个网站有直接关系。
我无邪 - 2006-7-4 1:59:00
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
Jasonself - 2006-7-4 1:59:00
2006-07-04,01:39:07
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"D:\瑞星杀毒软件\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RavMon><D:\瑞星杀~1\RAVMON.EXE -SYSTEM> []
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\system32\SoDAHK.DLL> [Sohu.com Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{5EED7056-B89D-4DE8-A060-D285EA746795}><C:\WINDOWS\system32\mshfmm.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Vision><> []
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
==================================
服务
[EPSON Printer Status Agent2 / EPSONStatusAgent2]
<C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe><SEIKO EPSON CORPORATION>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Intel NCS NetService / NetSvc]
<C:\Program Files\Intel\NCS\Sync\NetSvc.exe><Intel(R) Corporation>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[P4P Service / P4P Service]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Rising Process Communication Center / RsCCenter]
<"D:\瑞星杀毒软件\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"D:\瑞星杀毒软件\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SDAgent Service / SDAgentService]
<><N/A>
==================================
浏览器加载项
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr1.dll, Tencent>
[CPub Object]
{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <d:\P4P\sodaie.dll, Sohu.com Inc.>
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4546.dll, N/A>
[CaiShowBH Class]
{3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} <C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll, N/A>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[NetAccelerate Class]
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} <C:\WINDOWS\system32\MicrosoftNet.dll, N/A>
[XBTP03129 Class]
{6029B367-250A-4696-925C-641709CA7381} <C:\PROGRA~1\KUAISO~1\KUAISO~1.DLL, N/A>
[ActiveBHO Class]
{63C55A7F-6E29-8D4F-5C76-4F850F28D13A} <C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, >
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\DOCUME~1\董旭\LOCALS~1\Temp\SSLive.dll, TENCENT>
[Status Class]
{7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} <C:\Program Files\baigoo\BGooBHO.dll, >
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD>
[NewWebController Class]
{9ACEEE30-143F-471A-AA45-72B061FE7D60} <C:\WINDOWS\system32\WinSC.dll, N/A>
[estAliveObj Class]
{A2B7A0F0-B697-4A71-8D91-43443F57D7BB} <C:\WINDOWS\estAlive.dll, N/A>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, N/A>
[IEHlprObj Class]
{BA623AA0-9A82-4d0c-944C-0228CEA17780} <C:\Progra~1\NetMeeting\netinit.dll, Microsoft Corporation>
[Letscool System Helper]
{F0C15012-7DBD-4068-95A2-0A82DB03AC35} <C:\WINDOWS\system32\CoolBho.dll, N/A>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <, N/A>
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, N/A>
[我的订阅]
{8755CE6E-0BF7-4441-8751-FB728941B0B4} <d:\P4P\rss.dll, Sohu.com Inc.>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Tencent\qq\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\FlashGet\fgiebar.dll, Amaze Soft>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\金鹕山娇快煲译隲\IEBand.dll, N/A>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, N/A>
[全能助手广告拦截专家]
{ED51E9A3-16C5-4236-99E0-9F093B021433} <d:\windows优化王\AssistIEBar.dll, 全能助手工作室>
[全能助手[资源管理器]伴侣]
{939802BD-EDC8-4EE3-9997-A65BE4657FFD} <D:\windows优化王\ExBar.dll, 全能助手工作室>
[搜狗工具条]
{DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} <d:\P4P\ToolBar.dll, Sohu.com Inc.>
[Kuaiso Toolsbar]
{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} <C:\Program Files\Kuaiso Toolsbar\kuaiso_06040_9598.dll, N/A>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, N/A>
[QuickTime Object]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <D:\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr1.dll, Tencent>
[CPub Object]
{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <d:\P4P\sodaie.dll, Sohu.com Inc.>
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4546.dll, N/A>
[Windows Genuine Advantage]
我无邪 - 2006-7-4 1:59:00
休息了,明天再来。
Jasonself - 2006-7-4 2:00:00
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.dll, Microsoft? Corporation>
[RealPlayer SMIL Download Handler]
{224E833B-2CC6-42D9-AE39-90B6A38A4FA2} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, N/A>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[RealPlayer RAM Download Handler]
{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[CaiShowBH Class]
{3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} <C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll, N/A>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[NetAccelerate Class]
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} <C:\WINDOWS\system32\MicrosoftNet.dll, N/A>
[XBTP03129 Class]
{6029B367-250A-4696-925C-641709CA7381} <C:\PROGRA~1\KUAISO~1\KUAISO~1.DLL, N/A>
[ActiveBHO Class]
{63C55A7F-6E29-8D4F-5C76-4F850F28D13A} <C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, >
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\DOCUME~1\董旭\LOCALS~1\Temp\SSLive.dll, TENCENT>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[金山快译(&K)]
{6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <D:\金鹕山娇快煲译隲\IEBand.dll, N/A>
[Kuaiso Toolsbar]
{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} <C:\Program Files\Kuaiso Toolsbar\kuaiso_06040_9598.dll, N/A>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Windows Media Services DRM Storage object]
{760C4B83-E211-11D2-BF3E-00805FBE84A6} <C:\WINDOWS\system32\drmstor.dll, Microsoft Corporation>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <D:\Thunder\Components\InMedia\MediaAddin05.dll, Thunder Networking Technologies,LTD>
[Status Class]
{7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} <C:\Program Files\baigoo\BGooBHO.dll, >
[我的订阅]
{8755CE6E-0BF7-4441-8751-FB728941B0B4} <d:\P4P\rss.dll, Sohu.com Inc.>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD>
[全能助手[资源管理器]伴侣]
{939802BD-EDC8-4EE3-9997-A65BE4657FFD} <D:\windows优化王\ExBar.dll, 全能助手工作室>
[NewWebController Class]
{9ACEEE30-143F-471A-AA45-72B061FE7D60} <C:\WINDOWS\system32\WinSC.dll, N/A>
[RealPlayer Stream Handler]
{A1A41E11-91DB-4461-95CD-0C02327FD934} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[estAliveObj Class]
{A2B7A0F0-B697-4A71-8D91-43443F57D7BB} <C:\WINDOWS\estAlive.dll, N/A>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[IEHlprObj Class]
{BA623AA0-9A82-4D0C-944C-0228CEA17780} <C:\Progra~1\NetMeeting\netinit.dll, Microsoft Corporation>
[Adobe PDF Reader]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroPDF.dll, Adobe Systems, Inc.>
[AUDIO__MID Moniker Class]
{CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[搜狗工具条]
{DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} <d:\P4P\ToolBar.dll, Sohu.com Inc.>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\FlashGet\fgiebar.dll, Amaze Soft>
[全能助手广告拦截专家]
{ED51E9A3-16C5-4236-99E0-9F093B021433} <d:\windows优化王\AssistIEBar.dll, 全能助手工作室>
[Letscool System Helper]
{F0C15012-7DBD-4068-95A2-0A82DB03AC35} <C:\WINDOWS\system32\CoolBho.dll, N/A>
[IERPCtl Class]
{FDC7A535-4070-4B92-A0EA-D9994BCC0DC5} <C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll, RealNetworks, Inc.>
[&使用迅雷下载]
<d:\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Thunder\Program\GetAllUrl.htm, N/A>
[>>彩信发送<<]
<res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[上传到QQ网络硬盘]
<D:\Tencent\qq\AddToNetDisk.htm, N/A>
[使用搜狗直通车下载]
<d:\P4P\dl.htm, N/A>
[使用网际快车下载]
<D:\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
<D:\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Tencent\qq\AddEmotion.htm, N/A>
[添加到“我的订阅”]
<d:\P4P\rss.htm, N/A>
[用QQ彩信发送该图片]
<D:\Tencent\qq\SendMMS.htm, N/A>
==================================
Jasonself - 2006-7-4 2:00:00
正在运行的进程
[PID: 684][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 744][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 772][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 820][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 832][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 992][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1068][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1188][D:\瑞星杀毒软件\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1220][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1296][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1352][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1408][D:\瑞星杀毒软件\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 26>
[D:\瑞星杀毒软件\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[D:\瑞星杀毒软件\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒软件\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒软件\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒软件\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒软件\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[D:\瑞星杀毒软件\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[D:\瑞星杀毒软件\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\瑞星杀毒软件\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒软件\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒软件\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\瑞星杀毒软件\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒软件\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\瑞星杀毒软件\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒软件\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[D:\瑞星杀毒软件\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\瑞星杀毒软件\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[D:\瑞星杀毒软件\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\瑞星杀毒软件\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\瑞星杀毒软件\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒软件\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒软件\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\瑞星杀毒软件\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\瑞星杀毒软件\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[D:\瑞星杀毒软件\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
[D:\瑞星杀毒软件\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[D:\瑞星杀毒软件\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\瑞星杀毒软件\Rising\Rav\RsStore.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[PID: 1680][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[C:\Program Files\TENCENT\Adplus\SSAddr1.dll] <Tencent><4, 1, 1, 18>
[C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll] <><1, 0, 0, 1>
[d:\Thunder\ComDlls\XunLeiBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[D:\瑞星杀毒软件\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[d:\WinRAR\rarext.dll] <N/A><N/A>
[D:\windows优化王\AssistQRunShell.dll] <全能助手工作室><3, 0, 0, 3>
[C:\WINDOWS\system32\xunleibho_v8.dll] <><4, 5, 1, 33>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.7.2006011200>
[C:\DOCUME~1\董旭\LOCALS~1\Temp\SSLive.dll] <TENCENT><4, 1, 1, 18>
[C:\Program Files\baigoo\BGooBHO.dll] <><1, 0, 0, 1>
[D:\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[PID: 1796][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\system32\E_SL2340.DLL] <SEIKO EPSON CORPORATION><2, 15, 0, 0>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 1932][D:\瑞星杀毒软件\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[D:\瑞星杀毒软件\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒软件\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒软件\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒软件\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 1968][D:\瑞星杀毒软件\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 28>
[D:\瑞星杀毒软件\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[D:\瑞星杀毒软件\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[D:\瑞星杀毒软件\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒软件\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒软件\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒软件\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒软件\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 312][D:\瑞星杀毒软件\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[D:\瑞星杀毒软件\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒软件\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 444][C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe] <SEIKO EPSON CORPORATION><1, 2, 0, 0>
[C:\WINDOWS\system32\EBAPI2.DLL] <SEIKO EPSON CORPORATION><1, 1, 0, 0>
[C:\Program Files\Common Files\EPSON\EBAPI\EBPLPT.DLL] <SEIKO EPSON CORPORATION><2, 14, 0, 0>
[PID: 1148][C:\WINDOWS\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.7801>
[PID: 1384][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] <Sohu.com Inc.><2, 0, 0, 17>
[C:\Program Files\Sogou PXP\vodsvr.dll] <Sohu.com Inc.><1, 1, 0, 4>
[C:\Program Files\Sogou PXP\PluginClient.dll] <Sohu.com Inc.><1, 0, 0, 22>
[d:\P4P\tbupdate.dll] <Sohu.com Inc.><1, 0, 0, 9>
[d:\P4P\p4pipc.dll] <Sohu.com Inc.><1, 0, 0, 11>
[PID: 1576][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1196][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3152][D:\木马克星\Iparmor.exe] <N/A><N/A>
[D:\木马克星\getportlistxp.dll] <><1, 0, 0, 1>
[D:\木马克星\socketinit.dll] <N/A><N/A>
[D:\木马克星\hookhookdll.dll] <N/A><N/A>
[D:\瑞星杀毒软件\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
Jasonself - 2006-7-4 2:01:00
[PID: 1784][D:\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[D:\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 14>
[D:\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\TIMProxy.dll] <tencent><0, 3, 2, 4>
[D:\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2005, 9, 1, 1>
[D:\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[D:\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[D:\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[D:\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[D:\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[D:\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\QRingMng.dll] <N/A><N/A>
[D:\Tencent\qq\PhoneAPI.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[D:\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[D:\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[D:\Tencent\qq\LongConnection.dll] <tencent><0, 3, 3, 8>
[D:\Tencent\qq\QQPet.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[D:\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[D:\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[D:\Tencent\qq\SCCore.dll] <N/A><N/A>
[D:\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[D:\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[D:\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[D:\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 141>
[D:\Tencent\qq\QQMagicFace.dll] <><1, 0, 0, 1>
[D:\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[D:\Tencent\qq\GroupConnection.dll] <Tencent><5, 0, 202, 30>
[D:\Tencent\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[D:\Tencent\qq\QQFileTransfer.dll] <Tencent><5, 0, 202, 40>
[D:\Tencent\qq\QQZip.dll] <tencent><0, 3, 2, 4>
[PID: 2220][D:\Tencent\qq\TIMPlatform.exe] <tencent><0, 3, 1, 8>
[D:\Tencent\qq\TIMProxy.dll] <tencent><0, 3, 2, 4>
[PID: 2588][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2188][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SoDAHK.DLL] <Sohu.com Inc.><1, 0, 1, 3>
[C:\WINDOWS\system32\xunleibho_v8.dll] <><4, 5, 1, 33>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.7.2006011200>
[C:\Program Files\TENCENT\Adplus\SSAddr1.dll] <Tencent><4, 1, 1, 18>
[d:\P4P\sodaie.dll] <Sohu.com Inc.><1, 1, 2, 8>
[d:\P4P\ToolBar.dll] <Sohu.com Inc.><1, 4, 5, 6>
[d:\P4P\autolink.dll] <Sohu.com Inc.><1.0.0.17>
[D:\Tencent\qq\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll] <><1, 0, 0, 1>
[C:\DOCUME~1\董旭\LOCALS~1\Temp\SSLive.dll] <TENCENT><4, 1, 1, 18>
[C:\Program Files\baigoo\BGooBHO.dll] <><1, 0, 0, 1>
[d:\Thunder\ComDlls\XunLeiBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[D:\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[PID: 1404][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SoDAHK.DLL] <Sohu.com Inc.><1, 0, 1, 3>
[C:\WINDOWS\system32\xunleibho_v8.dll] <><4, 5, 1, 33>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.7.2006011200>
[C:\Program Files\TENCENT\Adplus\SSAddr1.dll] <Tencent><4, 1, 1, 18>
[d:\P4P\sodaie.dll] <Sohu.com Inc.><1, 1, 2, 8>
[d:\P4P\ToolBar.dll] <Sohu.com Inc.><1, 4, 5, 6>
[d:\P4P\autolink.dll] <Sohu.com Inc.><1.0.0.17>
[D:\Tencent\qq\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll] <><1, 0, 0, 1>
[C:\DOCUME~1\董旭\LOCALS~1\Temp\SSLive.dll] <TENCENT><4, 1, 1, 18>
[C:\Program Files\baigoo\BGooBHO.dll] <><1, 0, 0, 1>
[d:\Thunder\ComDlls\XunLeiBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[D:\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[D:\瑞星杀毒软件\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 2656][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SoDAHK.DLL] <Sohu.com Inc.><1, 0, 1, 3>
[C:\WINDOWS\system32\xunleibho_v8.dll] <><4, 5, 1, 33>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.7.2006011200>
[C:\Program Files\TENCENT\Adplus\SSAddr1.dll] <Tencent><4, 1, 1, 18>
[d:\P4P\sodaie.dll] <Sohu.com Inc.><1, 1, 2, 8>
[d:\P4P\ToolBar.dll] <Sohu.com Inc.><1, 4, 5, 6>
[d:\P4P\autolink.dll] <Sohu.com Inc.><1.0.0.17>
[D:\Tencent\qq\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll] <><1, 0, 0, 1>
[C:\DOCUME~1\董旭\LOCALS~1\Temp\SSLive.dll] <TENCENT><4, 1, 1, 18>
[C:\Program Files\baigoo\BGooBHO.dll] <><1, 0, 0, 1>
[d:\Thunder\ComDlls\XunLeiBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[D:\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[PID: 2772][D:\瑞星杀毒软件\Rising\Rav\Rav.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 75>
[D:\瑞星杀毒软件\Rising\Rav\PlugIn\RsPgScan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
[D:\瑞星杀毒软件\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\瑞星杀毒软件\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\瑞星杀毒软件\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\瑞星杀毒软件\Rising\Rav\RavUI.Dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 60>
[D:\瑞星杀毒软件\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[D:\瑞星杀毒软件\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\瑞星杀毒软件\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\瑞星杀毒软件\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[D:\瑞星杀毒软件\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[D:\瑞星杀毒软件\Rising\Rav\RavUIMsg.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 25>
[D:\瑞星杀毒软件\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[D:\瑞星杀毒软件\Rising\Rav\RavQu.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
[PID: 3684][D:\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
Jasonself - 2006-7-4 2:01:00
小弟多谢~~
独孤豪侠 - 2006-7-4 2:07:00
[SDAgent Service / SDAgentService]
<><N/A>
这个服务怎么没文件?
Jasonself - 2006-7-4 2:09:00
这个……偶就不清楚了,偶是菜鸟……日志看不懂地~~大哥多帮忙,不过有点眼熟,可能是被我手动删掉的?
Jasonself - 2006-7-4 2:13:00
我看了msconfig里服务项里面这个服务制造商 未知,已停止,但是前面打着勾~
Jasonself - 2006-7-4 2:24:00
木马克星提示怀疑C:\WINDOWS\SYSTEM32\netsend.exe.tmp是灰格子。每次我双击IE或者我的电脑就会在很短时间内生成C:\WINDOWS\SYSTEM32\netsend.exe.tmp。还有个C:\WINDOWS\SYSTEM32\inituser.exe.tmp也是,不过不知道什么时候生成,木马克星开机时候报过2次这个文件,瑞星从来没报告发现过这个文件。郁闷,现在点IE要等好久好久~~CPU没到100也不弹出窗口来。(打开这个论坛窗口算我狗屎运了)…=。= 其他程序运行还感觉不出慢。
Jasonself - 2006-7-4 18:25:00
有人能帮我么?
我无邪 - 2006-7-4 21:53:00
你所说的,的确很可疑。
但在日志里却没有发现
你修复以下后,建议你再扫份日志粘上来。
进入控制面版的添加删除程序中卸载,MMSASS~1彩信,搜搜地址栏搜索(QQ搜索小助手)
关闭所有浏览窗口以及一些不必要的程序
运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4546.dll
C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll
C:\WINDOWS\system32\MicrosoftNet.dll
C:\Program Files\baigoo\BGooBHO.dll
C:\WINDOWS\system32\WinSC.dll
C:\WINDOWS\estAlive.dll
C:\PROGRA~1\MMSASS~1
C:\WINDOWS\system32\CoolBho.dll
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\system32\mshfmm.dll
重启
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
删除
C:\WINDOWS\system32\mshfmm.dll
C:\Program Files\TENCENT\Adplus
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4546.dll
C:\Program Files\CaiShow Tech\
C:\WINDOWS\system32\MicrosoftNet.dll
C:\Program Files\baigoo
C:\WINDOWS\system32\WinSC.dll
C:\WINDOWS\estAlive.dll
C:\PROGRA~1\MMSASS~1
C:\WINDOWS\system32\CoolBho.dll
水如烟雾 - 2006-7-11 8:43:00
我中了个跟你的类似的,不过叫做Trojan.Clicker.Agent.abu,是个流氓广告木马,同样生成这两个病毒文件,这里是解决方法,希望可以对你有点帮助。
http://www.5dblog.com/user1/shuiruyinwu/200607/282326.html
1
© 2000 - 2026 Rising Corp. Ltd.