dj11 - 2006-9-21 2:07:00
如题,一开机就是这样,根本不能干别的。是在一次打开陌生人的邮件后就这样了,这是啥病毒,如何搞定他。
CuDDi - 2006-9-21 2:25:00
掃描日記上來。看看
dj11 - 2006-9-21 4:49:00
桌面上有一可疑的文件“message.elm"删除不了。下面是扫描报告:
2006-09-21,04:32:29
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Zone Labs Client><"C:\Program Files\Zone Labs\Integrity Client\iclient.exe"> [Check Point Inc.]
<C4EBReg><"C:\progra~1\c4ebreg\c4ebreg.exe" /q> [IBM Global Services]
<Isamtray><"C:\progra~1\c4ebreg\isamtray.exe"> [IBM Global Services]
<ISSI EZUpdate Service><"c:\sdwork\issimsvc.exe"> [IBM Global Services]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINNT\system32\NavLogon.dll> [Symantec Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<AEIWLSTA.EXE><; AEIWLSTA.EXE> [Actiontec Electronics, Inc]
<AGRSMMSG><; AGRSMMSG.exe> [Agere Systems]
<C4EBReg><; "C:\progra~1\c4ebreg\c4ebreg.exe" /q> [IBM Global Services]
<ccApp><; "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [Symantec Corporation]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><; ctfmon.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<HotKeysCmds><; C:\WINNT\system32\hkcmd.exe> [Intel Corporation]
<IgfxTray><; C:\WINNT\system32\igfxtray.exe> [Intel Corporation]
<ISAMTray><; "C:\progra~1\c4ebreg\isamtray.exe"> [IBM Global Services]
<ISSI EZUpdate Service><; "c:\sdwork\issimsvc.exe"> [IBM Global Services]
<Mysee Alert><; "C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray> []
<NMGameX_AutoRun><; C:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa> [NMGameX]
<qcsszjcz><; c:\chenhu2\chenqxms.exe> []
<Synchronization Manager><; mobsync.exe /logon> [Microsoft Corporation]
<SynTPEnh><; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [Synaptics, Inc.]
<SynTPLpr><; C:\Program Files\Synaptics\SynTP\SynTPLpr.exe> [Synaptics, Inc.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> []
<TpShocks><; TpShocks.exe> [IBM Corp.]
<TrackPointSrv><; tp4serv.exe> [IBM Corporation]
<vptray><; C:\PROGRA~1\SYMANT~1\VPTray.exe> [Symantec Corporation]
<WangWang><; "d:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"> []
==================================
启动文件夹
服务
[Indexing Data / BNESS]
<C:\WINNT\SYSTEM32\RUNDLL32.EXE C:\WINNT\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Symantec Event Manager / ccEvtMgr]
<C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
<C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch]
<C:\Program Files\Symantec AntiVirus\DefWatch.exe><Symantec Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[IBM PM Service / IBMPMSVC]
<C:\WINNT\system32\ibmpmsvc.exe><N/A>
[IBM Standard Asset Manager Service / ISAMSvc]
<C:\progra~1\c4ebreg\c4ebreg.exe><IBM Global Services>
[ISSI EZUpdate / ISSIMon]
<c:\sdwork\issimsvc.exe><IBM Global Services>
[Pml Driver HPZ12 / Pml Driver HPZ12]
<C:\WINNT\system32\spool\DRIVERS\W32X86\3\HPZipm12.exe><HP>
[SavRoam / SavRoam]
<C:\Program Files\Symantec AntiVirus\SavRoam.exe><symantec>
[Symantec Network Drivers Service / SNDSrvc]
<C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus]
<C:\Program Files\Symantec AntiVirus\Rtvscan.exe><Symantec Corporation>
[TrueVector Internet Monitor / vsmon]
<C:\WINNT\system32\ZoneLabs\vsmon.exe -service><Check Point Inc.>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[LinkFilter Class]
{4022F902-ABC7-4C79-924F-BB26F1D355A2} <C:\WINNT\system32\diybar2\diybar2.dll, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, N/A>
[T2BHO Class]
{B1D147E7-873E-4909-8127-695D9BB78728} <C:\WINNT\Downloaded Program Files\CONFLICT.1\barhelp24.0.dll, HDT, Inc.>
[IEHlprObj Class]
{CE7C3CF0-4B15-11D1-ABED-709549C10000} <C:\WINNT\system32\IEHelper.dll, >
[QuickBtn]
{D1BB7CF4-4463-4e91-88D7-ECC3CE0A13B7} <C:\Program Files\CoolWebsite\QuickLink.dll, N/A>
[bho Class]
{ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} <C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll, 深圳世强软件开发部>
[金山词霸]
{9A687CA6-D585-4947-9ED9-BE96071F5CD9} <C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, N/A>
[虎翼DIY吧!]
{0A00D11E-B1E7-44b5-AD88-C9190876AAC4} <C:\WINNT\system32\diybar2\diybar2.dll, N/A>
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINNT\system32\CMBEdit.dll, >
[Installer Class]
{28E0FA88-ABA8-4937-A247-3031F1A11165} <C:\WINNT\system32\diybar2\diybar2.dll, N/A>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\AliEdit.dll, www.alipay.com>
[Downloader Class]
{5932517A-3326-4439-A708-1C98EDB5C549} <C:\WINNT\system32\iMopDl.dll, >
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINNT\DOWNLO~1\PHOTO_~1.OCX, N/A>
[E&xport to Microsoft Excel]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[Google 搜索(&G)]
<res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[反向链接]
<res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html, N/A>
[类似网页]
<res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html, N/A>
[缓存的网页快照]
<res://c:\program files\google\GoogleToolbar2.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
<res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html, N/A>
dj11 - 2006-9-21 4:49:00
==================================
正在运行的进程
[PID: 156][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 180][\??\C:\WINNT\system32\csrss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 176][\??\C:\WINNT\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.6997>
[C:\WINNT\system32\NavLogon.dll] <Symantec Corporation><9.0.3.1000>
[C:\WINNT\system32\igfxsrvc.dll] <Intel Corporation><3.0.0.2249>
[C:\WINNT\system32\hccutils.DLL] <Intel Corporation><3.0.0.2249>
[PID: 228][C:\WINNT\system32\services.exe] <Microsoft Corporation><5.00.2195.7035>
[C:\WINNT\system32\dmserver.dll] <VERITAS Software Corp.><2195.6605.297.3>
[PID: 240][C:\WINNT\system32\lsass.exe] <Microsoft Corporation><5.00.2195.7011>
[PID: 364][C:\WINNT\system32\ibmpmsvc.exe] <N/A><N/A>
[PID: 388][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 440][C:\WINNT\System32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[C:\Program Files\Zone Labs\Integrity Client\zlxeap.dll] <Check Point Inc.><6.0.202.000>
[PID: 492][C:\WINNT\system32\spoolsv.exe] <Microsoft Corporation><5.00.2195.7059>
[C:\WINNT\system32\HPBMMON.DLL] <Hewlett-Packard><10.00.16>
[C:\WINNT\system32\hpdomon.dll] <Hewlett-Packard><03.42.00>
[C:\WINNT\system32\HPBHealr.dll] <N/A><N/A>
[PID: 540][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe] <Symantec Corporation><2.2.2.008>
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] <Symantec Corporation><2.2.2.008>
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL] <Symantec Corporation><2.2.2.008>
[PID: 596][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe] <Symantec Corporation><2.2.2.008>
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] <Symantec Corporation><2.2.2.008>
[PID: 612][C:\Program Files\Symantec AntiVirus\DefWatch.exe] <Symantec Corporation><9.0.3.1000>
[PID: 676][C:\progra~1\c4ebreg\c4ebreg.exe] <IBM Global Services><6.11>
[C:\progra~1\c4ebreg\osprules.dll] <IBM Global Services><1.8>
[C:\progra~1\c4ebreg\python23.dll] <Python Software Foundation><2.3.4>
[C:\progra~1\c4ebreg\pmemw.dll] <N/A><N/A>
[PID: 736][c:\sdwork\issimsvc.exe] <IBM Global Services><2.09>
[PID: 768][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe] <Microsoft Corporation><7.00.9064.9150>
[PID: 872][C:\WINNT\system32\regsvc.exe] <Microsoft Corporation><5.00.2195.6701>
[PID: 888][C:\WINNT\system32\MSTask.exe] <Microsoft Corporation><4.71.2195.6972>
[PID: 964][C:\Program Files\Symantec AntiVirus\Rtvscan.exe] <Symantec Corporation><9.0.3.1000>
[C:\WINNT\system32\CBA.DLL] <Intel? Corporation><6.12.0.130 E>
[C:\WINNT\system32\MsgSys.dll] <Intel? Corporation><6.12.0.130 E>
[C:\WINNT\system32\NTS.dll] <Intel? Corporation><6.12.0.130 E>
[C:\WINNT\system32\PDS.DLL] <Intel? Corporation><6.12.0.130 E>
[C:\Program Files\Symantec AntiVirus\NAVLU.dll] <Symantec Corporation><9.0.3.1000>
[C:\Program Files\Symantec AntiVirus\I2ldvp3.dll] <Symantec Corporation><9.0.3.1000>
[C:\Program Files\Symantec AntiVirus\ecmldr32.DLL] <Symantec Corp.><1.1.0.3>
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] <Symantec Corporation><9.3.0.28>
[C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL] <Symantec Corporation><9.0.3.1000>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060919.019\ecmsvr32.dll] <Symantec Corporation><61.2.1.10>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060919.019\NAVEX32a.DLL] <Symantec Corporation><20061.2.0.26>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060919.019\NAVENG32.DLL] <Symantec Corporation><20061.2.0.26>
[C:\Program Files\Symantec AntiVirus\IMail.dll] <Symantec Corporation><9.0.3.1000>
[C:\Program Files\Symantec AntiVirus\NotesExt.dll] <Symantec Corporation><9.0.3.1000>
[C:\Program Files\Symantec AntiVirus\vpmsece2.dll] <Symantec Corporation><9.0.3.1000>
[C:\Program Files\Symantec AntiVirus\DecSDK.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2ID.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2ZIP.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2SS.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2GZIP.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2CAB.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2LHA.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2ARJ.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2TNEF.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2LZ.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2AMG.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2TAR.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2RTF.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Symantec AntiVirus\Dec2Text.dll] <Symantec Corporation><3.02.12.09>
[C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll] <Symantec Corporation><9.0.3.1000>
[PID: 1044][C:\WINNT\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0100>
[PID: 1064][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 1076][C:\WINNT\System32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 1380][C:\WINNT\Explorer.exe] <Microsoft Corporation><5.00.3700.6690>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.1.2003110300>
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] <Symantec Corporation><9.0.3.1000>
[PID: 1432][D:\ISH1 KT共享文件夹\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[PID: 460][D:\ISH1 KT共享文件夹\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.JS Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
oo123oo3 - 2006-9-21 6:25:00
启动项目--注册表
删除
<NMGameX_AutoRun><; C:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa> [NMGameX
修复
.VBS Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.JS Error. [C:\WINNT\system32\WScript.exe "%1" %*]
删除文件
NMGameX.dll
© 2000 - 2026 Rising Corp. Ltd.