huaqianyuexia - 2006-9-5 11:02:00
高手帮忙看下日志!
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<Microsoft TAP><C:\WINDOWS\system32\AppEvent.exe> []
<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []
<Start><Start.exe> []
<ScanRegistry><c:\windows\update1.exe> []
<RealUpdate><C:\Program Files\Common Files\update\update.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<KB83072651><C:\WINDOWS\system32\AppEvent.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<NTdhcp><C:\WINDOWS\system32\NTdhcp.exe> []
<CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<zt><C:\Program Files\Intel\rundll32.exe> []
<Systems32><C:\WINDOWS\system32\Server.exe> []
<SOUNDM><winsmd.exe> []
<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []
<Start><Start.exe> []
<Tray><C:\WINDOWS\command\rundll32.exe> []
<wdfmgr32><C:\WINDOWS\system32\wdfmgr32.exe> []
<TProgram><C:\WINDOWS\SMSS.EXE> [MUxv7zlg6nPw3CBVSE93]
<ToP><C:\WINDOWS\LSASS.exe> [CoSmk]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CheckFaultKernel><C:\WINDOWS\system32\mswdm.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><KB399952M.LOG> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{288BD9BD-F0DC-46B1-81B5-2B61DF8077CE}><C:\WINDOWS\system32\CCG1.DLL> []
<{6E44887F-5214-41F2-AB46-4728735C4CC6}><C:\Program Files\Internet Explorer\PLUGINS\system.sys> []
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys> []
<{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><C:\Program Files\Internet Explorer\IEXPLORE.Dat> []
<{CF49F9F2-A8D3-464F-83EC-6AFC6573C267}><C:\WINDOWS\system32\jhlog3.DLL> []
<{BEEADE0D-47BB-4F20-AD26-5E5F172BF97C}><C:\Program Files\Internet Explorer\PLUGINS\system32.sys> []
<{8EF697AE-7C40-48EF-B3D7-6EF503893A88}><C:\WINDOWS\system32\wintfm.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<DVDBurn><C:\WINDOWS\Downloaded Program Files\AfxEdit.dll> []
<DLMon><C:\WINDOWS\system32\DLMain.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ATIModeChange><; Ati2mdxx.exe> [ATI Technologies, Inc.]
<ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> []
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<SoundMan><; SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
==================================
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\Admin\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
[暴风娱乐]
<C:\Documents and Settings\Admin\「开始」菜单\程序\启动\暴风娱乐.lnk><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><N/A>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Rising Process Communication Center / RsCCenter]
<C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><rising>
[RsRavMon Service / RsRavMon]
<C:\PROGRAM FILES\RISING\RAV\Ravmond.exe><Beijing Rising Technology Co., Ltd.>
huaqianyuexia - 2006-9-5 11:03:00
浏览器加载项
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, N/A>
[PRBHO.HTMLDocumentCtrl]
{AAC73F50-03DD-47E5-AD18-FDD65BF29E3D} <C:\WINDOWS\system32\ZComBHO.dll, zcom>
[PrjZKBaiduBHO.ZKBaiduBHO]
{BBF3E65D-762A-41AC-BFDA-7C6D97E65A73} <C:\WINDOWS\system32\ZKBaiduBHO.dll, zcom>
[shdocvwhlp Class]
{BE442802-3911-46E0-B227-076B15A4EAD3} <C:\WINDOWS\system32\mskey16.dll, MicroCropration>
[豪杰超级解霸V8]
{367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\Herosoft\HeroV8\STHSDVD.EXE, herosoft>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[易趣购物]
{DE607141-AC19-421e-865A-5D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <E:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[EWA Control]
{18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~1.OCX, Synacast>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[HHCtrl Object]
{41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <E:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[List Control]
{70CACCCA-8B83-4BCB-B2D1-188E9A495527} <C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~2.OCX, >
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[PRBHO.HTMLDocumentCtrl]
{AAC73F50-03DD-47E5-AD18-FDD65BF29E3D} <C:\WINDOWS\system32\ZComBHO.dll, zcom>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[PrjZKBaiduBHO.ZKBaiduBHO]
{BBF3E65D-762A-41AC-BFDA-7C6D97E65A73} <C:\WINDOWS\system32\ZKBaiduBHO.dll, zcom>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[shdocvwhlp Class]
{BE442802-3911-46E0-B227-076B15A4EAD3} <C:\WINDOWS\system32\mskey16.dll, MicroCropration>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
<E:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<E:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[百度Flash搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/FLASHSEARCH.HTM, N/A>
[百度mp3搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
[百度信息快递搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIE.HTM, N/A>
[百度图片搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
[百度搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
[百度新闻搜索]
<res://C:\WINDOWS\DOWNLO~1\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
[豪杰超级解霸V8实时播放]
<C:\Herosoft\HeroV8\MPURLGET.HTM, N/A>
huaqianyuexia - 2006-9-5 11:03:00
正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 496][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 520][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 572][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[PID: 584][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 744][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[PID: 812][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 880][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 940][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 1028][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 1208][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 1520][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\WINDOWS\system32\wintfm.dll] <N/A><N/A>
[C:\WINDOWS\system32\Rsvtub.dll] <N/A><N/A>
[C:\WINDOWS\system32\KB3999526.LOG] <N/A><N/A>
[C:\WINDOWS\Downloaded Program Files\swflash.dll] <N/A><N/A>
[C:\WINDOWS\system32\DLMon.dll] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\WINDOWS\system32\AppCheck.dll] <N/A><N/A>
[C:\WINDOWS\system32\mskey16.dll] <MicroCropration><1, 0, 0, 1>
[PID: 1740][C:\WINDOWS\system32\winmer.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[PID: 1768][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3510>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[PID: 1784][C:\WINDOWS\system32\NTdhcp.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[PID: 1904][C:\WINDOWS\system32\Server.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[PID: 1940][C:\WINDOWS\system32\Realplayer.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[PID: 2016][C:\WINDOWS\system32\wdfmgr32.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[PID: 204][C:\WINDOWS\system32\Ati2evxx.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 1116][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[PID: 1936][C:\WINDOWS\system32\VKTServ.exe] <Microsoft Corporation><1.1.2600.2180>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 2532][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 2652][C:\windows\update1.exe] <N/A><N/A>
[C:\windows\KB399952M.LOG] <N/A><N/A>
huaqianyuexia - 2006-9-5 11:03:00
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\WINDOWS\system32\wintfm.dll] <N/A><N/A>
[PID: 2672][C:\Program Files\Common Files\update\update.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[PID: 2832][C:\Program Files\storm\ZComService.exe] <智通无限><3.4.4.1>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\Program Files\storm\skin.dll] <http://www.zcom.com/><1.0.0.1>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\WINDOWS\system32\wintfm.dll] <N/A><N/A>
[PID: 2252][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[PID: 2860][C:\DOCUME~1\Admin\LOCALS~1\Temp\CCG0.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[PID: 3672][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[PID: 1484][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\WINDOWS\system32\ZComBHO.dll] <zcom><1.00>
[C:\WINDOWS\system32\ZKBaiduBHO.dll] <zcom><1.00>
[C:\WINDOWS\system32\mskey16.dll] <MicroCropration><1, 0, 0, 1>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <><17, 0, 0, 6>
[C:\WINDOWS\system32\wintfm.dll] <N/A><N/A>
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] <Adobe Systems, Inc.><9,0,16,0>
[PID: 1280][C:\WINDOWS\LSASS.exe] <CoSmk><0.00.0075>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[PID: 2296][C:\DOCUME~1\Admin\LOCALS~1\Temp\CCG0.exe] <N/A><N/A>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[PID: 1720][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[PID: 1832][C:\Documents and Settings\Admin\桌面\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINDOWS\KB399952M.LOG] <N/A><N/A>
[C:\WINDOWS\system32\KB896475.log] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system32.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\system32\CCG1.DLL] <N/A><N/A>
[C:\WINDOWS\system32\wintfm.dll] <N/A><N/A>
huaqianyuexia - 2006-9-5 11:04:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE Error. [WindowFiles]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
baohe - 2006-9-5 11:08:00
【回复“huaqianyuexia”的帖子】
第一次见到品种如此齐全的日志。
如果你有系统GHOST备份,就用GHOST备份恢复系统吧,兄弟!
比杀毒省事多了。
huaqianyuexia - 2006-9-5 11:10:00
我这里没有GHOST!要重做系统吗?
独孤豪侠 - 2006-9-5 11:11:00
没有就格盘重装吧.....如果mopery在的话他也许对你电脑里的样本非常感兴趣..........
huaqianyuexia - 2006-9-5 11:12:00
郁闷!除了重装就没有别的办法了吗?
baohe - 2006-9-5 11:16:00
| 引用: |
【huaqianyuexia的贴子】郁闷!除了重装就没有别的办法了吗?
……………… |
升级病毒库。
在DOS下杀毒。
试试吧。
baohe - 2006-9-5 11:20:00
| 引用: |
【独孤豪侠的贴子】 DOS下不是要做DOS启动盘????? ……………… |
可以用瑞星2006光盘启动到DOS杀毒环境。
© 2000 - 2026 Rising Corp. Ltd.