瑞星卡卡安全论坛
ぇ小心病毒ぇ - 2006-11-1 17:28:00
发现病毒不会清理找高手帮帮忙啊~~~帮忙看下日历~~~如果有办法请详细留言我比较笨



~~~
附件:
7056272006111172238.BMP
ぇ小心病毒ぇ - 2006-11-1 17:31:00
2006-11-01,16:39:29
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<DeviceDiscovery><C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe> [Hewlett-Packard]
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<HP Software Update><"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"> [Hewlett-Packard]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<stdup><> [N/A]
==================================
ぇ小心病毒ぇ - 2006-11-1 17:32:00
启动文件夹
N/A
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[hpdj / hpdj]
<><N/A>
[Rising Proxy Service / RfwProxySrv]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[VIA Rhine Family Fast Ethernet Adapter Driver / FETNDIS]
<system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
[HOOKAPI / HOOKAPI]
<\??\C:\PROGRAM FILES\RISING\RAV\HookApi.Sys><瑞星软件有限公司>
[HookCont / HookCont]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[kmsinput / kmsinput]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[npkcrypt / npkcrypt]
<\??\E:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[NPPTNT2 / NPPTNT2]
<\??\C:\WINDOWS\system32\npptNT2.sys><INCA Internet Co., Ltd.>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[SSProt / SSProt]
<\SystemRoot\system32\drivers\SSProt.sys><腾讯科技(深圳)有限公司>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[ViaIde / ViaIde]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[VIA AC'97 Audio Controller (WDM) / VIAudio]
<system32\drivers\viaudio.sys><VIA Technologies, Inc.>
==================================
ぇ小心病毒ぇ - 2006-11-1 17:32:00
浏览器加载项
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\qq\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <E:\qq\QQIEHelper.dll, N/A>
[BitComet工具栏]
{3F1ABCDB-A875-46c1-8345-B72A4567E486} <E:\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Ad Engine]
{077FD0C3-1291-4104-A356-41E36B252682} <C:\Program Files\Yayad\AdCore.dll, CDM>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[BitComet工具栏]
{3F1ABCDB-A875-46C1-8345-B72A4567E486} <E:\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <E:\qq\QQIEHelper.dll, N/A>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\DOCUME~1\chenjun\LOCALS~1\Temp\SSLive.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷5\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\DOWNLO~1\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
<D:\迅雷5\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\迅雷5\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<E:\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<E:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\qq\SendMMS.htm, N/A>
==================================
ぇ小心病毒ぇ - 2006-11-1 17:33:00
正在运行的进程
[PID: 604][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 724][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 892][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1116][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1196][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1296][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1328][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1400][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1496][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1748][c:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 33]
[c:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 13]
[c:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 6]
[c:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 21]
[c:\program files\rising\rfw\psapi.dll] [Microsoft Corporation, 4.00]
[c:\program files\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[c:\program files\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 9]
[c:\program files\rising\rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1964][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\hpzsnt09.dll] [HP, 2.236.4.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 736][C:\WINDOWS\system32\inetsrv\inetinfo.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1060][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1856][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 52]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[c:\program files\rising\rfw\PSAPI.DLL] [Microsoft Corporation, 4.00]
[PID: 516][C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe] [Hewlett-Packard, 1, 0, 0, 1]
[C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodvd08.dll] [Hewlett-Packard, 2, 0, 2, 2]
[C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxm08.dll] [Hewlett-Packard Co., 4.2.0.127]
[PID: 1260][C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe] [Hewlett-Packard, 1, 0, 0, 2]
[PID: 1488][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2024][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 308][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1704][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 3844][D:\MagicSet-v7.15\MagicSet\winspeed.exe] [Super Rabbit Soft, 7.46]
[D:\MagicSet-v7.15\MagicSet\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[D:\MagicSet-v7.15\MagicSet\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\WINDOWS\system32\shlobj71.ocx] [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
[C:\WINDOWS\system32\vbalIml6.ocx] [vbAccelerator, 2.00.0001]
[C:\WINDOWS\system32\vbalExpBar6.ocx] [vbAccelerator, 1.00.0009]
[C:\WINDOWS\system32\SSubTmr6.dll] [vbAccelerator, 1.01.0003]
[C:\WINDOWS\system32\fldrvw71.ocx] [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
[PID: 2092][E:\qq\QQ.exe] [TENCENT, 0, 0, 0, 0]
[E:\qq\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[E:\qq\QQHelperDll.dll] [, 1, 0, 0, 1]
[E:\qq\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 160]
[E:\qq\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[E:\qq\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[E:\qq\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[E:\qq\QQAPI.dll] [, 1, 0, 0, 1]
[E:\qq\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[E:\qq\LoginCtrl.dll] [, 1, 0, 0, 1]
[E:\qq\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 3, 2, 1]
[E:\qq\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[E:\qq\QQRes.dll] [tencent, 1, 0, 0, 1]
[E:\qq\QQMainFrame.dll] [N/A, N/A]
[E:\qq\CQQApplication.dll] [N/A, N/A]
[E:\qq\NewSkin.dll] [, 1, 0, 0, 1]
[E:\qq\HostingMgr.dll] [, 1, 0, 0, 1]
[E:\qq\CameraDll.dll] [, 1, 0, 0, 1]
[E:\qq\MailSummary.dll] [, 1, 0, 0, 1]
[E:\qq\QQSpace.dll] [, 1, 0, 0, 1]
[E:\qq\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[E:\qq\QQGroupMng.dll] [, 1, 0, 0, 1]
[E:\qq\GroupLive.dll] [N/A, N/A]
[E:\qq\UserDefinedHead.dll] [, 1, 0, 0, 1]
[E:\qq\QQPlugin.dll] [N/A, N/A]
[E:\qq\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[E:\qq\QRingMng.dll] [N/A, N/A]
[E:\qq\PhoneAPI.dll] [, 1, 0, 0, 1]
[E:\qq\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[E:\qq\LongConnection.dll] [tencent, 5, 0, 200, 160]
[E:\qq\QQAvatar.dll] [N/A, N/A]
[E:\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[E:\qq\QQPet.dll] [, 1, 0, 0, 1]
[E:\qq\QQSysMsgMng.dll] [N/A, N/A]
[E:\qq\BQQApplication.dll] [N/A, N/A]
[E:\qq\CommercesMng.dll] [, 1, 0, 0, 1]
[E:\qq\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
ぇ小心病毒ぇ - 2006-11-1 17:33:00
[E:\qq\QQUdpGetFileLib.dll] [tencent, 0, 2, 2, 3]
[E:\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
[E:\qq\QQSceneMng.dll] [N/A, N/A]
[E:\qq\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 0, 6, 60]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[E:\qq\QQAllInOne.dll] [N/A, N/A]
[E:\qq\SCCore.dll] [N/A, N/A]
[E:\qq\QQCustomFace.dll] [N/A, N/A]
[E:\qq\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\qq\GroupConnection.dll] [Tencent, 5, 0, 202, 170]
[E:\qq\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[PID: 1612][E:\qq\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[E:\qq\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3652][C:\Program Files\Rising\Rav\RAVTASK.EXE] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 3244][C:\Program Files\Rising\Rav\RAVMON.EXE] [Beijing Rising Technology Co., Ltd., 18, 0, 1, 39]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 2680][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 848][E:\BitComet\BitComet.exe] [www.BitComet.com, 0.70]
[E:\BitComet\dbghelp.dll] [Microsoft Corporation, 6.3.0011.3 (DbgBuild.040120-1256)]
[PID: 1636][D:\迅雷5\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.3.0.220]
[D:\迅雷5\Program\UpdateDownload.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
[D:\迅雷5\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 71]
[D:\迅雷5\Program\log4cplus.dll] [, 1, 0, 2, 1]
[D:\迅雷5\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[D:\迅雷5\Program\asyn_dns.dll] [N/A, N/A]
[D:\迅雷5\Program\msgmanage.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
[D:\迅雷5\Program\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
[D:\迅雷5\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
[C:\WINDOWS\system32\MSXML4.dll] [Microsoft Corporation, 4.10.9404.0]
[D:\迅雷5\Program\FloatBar.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[D:\迅雷5\Plugins\TingTing\TingTing.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
[D:\迅雷5\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 11]
[D:\迅雷5\Components\InMedia\iEmbed04.dll] [ , 2, 3, 0, 37]
[D:\迅雷5\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 8]
[D:\迅雷5\Program\iTargetAd.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 55]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 2948][C:\Program Files\Real\RealPlayer\RealPlay.exe] [RealNetworks, Inc., 6.0.12.1069]
[C:\WINDOWS\system32\PNCRT.dll] [Real Networks, Inc, 6.0.0.0]
[C:\Program Files\Common Files\Real\Common\objb3201.dll] [RealNetworks, Inc., 0.1.0.6244]
[E:\新建文件夹 (5)\rpplugins\rpap3260.dll] [RealNetworks, Inc., 6.0.9.2954]
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.3985]
[E:\新建文件夹 (5)\lang\cdplay_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\dbcomp_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\embed_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\gemctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\pngui_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\pdgenxfer_cn.dll] [N/A, N/A]
[E:\新建文件夹 (5)\lang\rjctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjeq_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjres_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjskin_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjviz_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjfade_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjdlg_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjmisc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rjprog_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rpapp_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rpclsvc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rpclutil_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[E:\新建文件夹 (5)\lang\rpdemand_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[E:\新建文件夹 (5)\lang\rpdsplyr_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rpgutil_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rpmnpane_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rpplylst_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\rpwebctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\tcdinfo_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\tclsvc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\tdwnmgr_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\tmp3_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\twave_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\teasdk_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\tearm_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\tmdedit_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[E:\新建文件夹 (5)\lang\mydevices_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[E:\新建文件夹 (5)\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.3027]
[C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll] [RealNetworks, Inc., 0.1.0.3749]
[C:\Program Files\Real\RealPlayer\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.2828]
[C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] [RealNetworks, Inc., 6.0.8.2469]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols1.dll] [RealNetworks, Inc., 6.0.1.2153]
[C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll] [RealNetworks, Inc., 1.0.0.3914]
[E:\新建文件夹 (5)\rpplugins\rpmn3260.dll] [RealNetworks, Inc., 6.0.9.2851]
[E:\新建文件夹 (5)\rpplugins\rpms3260.dll] [RealNetworks, Inc., 6.0.1.2188]
[E:\新建文件夹 (5)\rpplugins\MPACore.dll] [RealNetworks, Inc., 1.0.3.2207]
[E:\新建文件夹 (5)\rpplugins\myde3260.dll] [RealNetworks, Inc., 6.0.10.2416]
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.2629]
[E:\新建文件夹 (5)\plugins\rjrmjpln.dll] [RealNetworks, Inc., 1.0.3.2164]
[C:\Program Files\Common Files\Real\Common\pnen3260.dll] [RealNetworks, Inc., 10.0.0.895]
[C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] [RealNetworks, Inc., 10.1.0.795]
[C:\Program Files\Common Files\Real\Plugins\vidsite.dll] [RealNetworks, Inc., 10.0.0.868]
[C:\Program Files\Common Files\Real\Plugins\clntxres.dll] [RealNetworks, Inc., 10.0.0.3446]
[C:\Program Files\Real\RealPlayer\rpplugins\rjbe3260.dll] [RealNetworks, Inc., 6.0.4.1981]
[C:\Program Files\Common Files\Real\Plugins\smplfsys.dll] [RealNetworks, Inc., 10.0.0.1654]
[C:\Program Files\Common Files\Real\Plugins\ramfformat.dll] [RealNetworks, Inc., 10.0.0.2111]
[C:\Program Files\Common Files\Real\Plugins\rmfformat.dll] [RealNetworks, Inc., 10.0.0.1089]
[C:\Program Files\Common Files\Real\Plugins\rarender.dll] [RealNetworks, Inc., 10.0.0.874]
[C:\Program Files\Common Files\Real\Codecs\hxltcolor.dll] [RealNetworks, Inc., 10.0.0.725]
[C:\Program Files\Common Files\Real\Common\rjbviz.dll] [RealNetworks, Inc., 1.0.2.3809]
[C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv] [RealNetworks, Inc., 1.0.0.2]
[C:\Program Files\Common Files\Real\Visualizations\Fire.rpv] [RealNetworks, Inc., 1.0.0.1]
[C:\Program Files\Common Files\Real\Visualizations\FreqBands.rpv] [RealNetworks, Inc., 1.0.0.2]
[C:\Program Files\Common Files\Real\Visualizations\Nebula.rpv] [N/A, N/A]
[C:\Program Files\Common Files\Real\Plugins\authmgr.dll] [RealNetworks, Inc., 10.0.0.1317]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols2.dll] [RealNetworks, 6.0.1.2153]
[C:\Program Files\Common Files\Real\RCAPlugins\gemx3201.dll] [RealNetworks, Inc., 0.1.0.5786]
[C:\Program Files\Common Files\Real\Visualizations\CosmicBelt.rpv] [N/A, N/A]
[C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll] [RealNetworks, Inc., 0.1.0.3427]
[E:\新建文件夹 (5)\rpplugins\rpgu3260.dll] [RealNetworks, Inc., 6.0.10.2188]
[C:\Program Files\Common Files\Real\Plugins\rvrender.dll] [RealNetworks, Inc., 10.0.0.1259]
[C:\Program Files\Common Files\Real\Codecs\cook.dll] [RealNetworks, Inc., 10.0.0.1625]
[C:\Program Files\Common Files\Real\Codecs\RV40.DLL] [RealNetworks, Inc., 10.0.0.1355]
[C:\Program Files\Common Files\Real\Codecs\drvc.dll] [RealNetworks, Inc., 10.0.0.1355]
[PID: 3540][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3427]
[PID: 3092][D:\RogueCleaner.exe\SREng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
==================================
ぇ小心病毒ぇ - 2006-11-1 17:34:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
我是来来 - 2006-11-1 18:04:00
[E:\新建文件夹 (5)\rpplugins\rpmn3260.dll] [RealNetworks, Inc., 6.0.9.2851]
[E:\新建文件夹 (5)\rpplugins\rpms3260.dll] [RealNetworks, Inc., 6.0.1.2188]
[E:\新建文件夹 (5)\rpplugins\MPACore.dll] [RealNetworks, Inc., 1.0.3.2207]
[E:\新建文件夹 (5)\rpplugins\myde3260.dll] [RealNetworks, Inc., 6.0.10.2416]
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.2629]
不知道是什么.
帅的被贼砍 - 2006-11-1 18:09:00
应该是 RealPlayer 播放软件里的
ぇ小心病毒ぇ - 2006-11-1 20:02:00
大哥啊怎么会啊~~~RealPlayer里是那个啊和我说下我删不要吓我啊~~~我电脑全是电影啊~~~
我不是你的天使 - 2006-11-1 20:08:00
在注册表删除:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
以及
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[SDAgent Service / SDAgentService]
<C:\Program Files\Common Files\smartde\sde.exe><N/A>
重启后删除:
C:\PROGRA~1\COMMON~1\system\msdc32.dll
C:\PROGRA~1\COMMON~1\system\mod\mstd.dll
C:\Program Files\Common Files\smartde\sde.exe
还有一些浏览器插件,那些用HijackThis来做比较方便。
【提示】
若正常模式下无法解决
建议进入安全模式下操作
【小常识】
若文件找不到或无法删除文件
建议进入安全模式下删除
打开我的电脑
在工具栏中点击--工具--文件夹选项--查看
勾选“显示所有文件及文件夹”
同时把“隐藏受保护的操作系统文件(推荐)”前的勾去掉
然后再进行查找一下
或利用KILLBOX来删除
KILLBOX下载:
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
或利用费尔木马强力清除助手来删除
费尔木马强力清除助手使用参考:
http://www.xfilt.com/tech/trojan-horse.htm
ぇ小心病毒ぇ - 2006-11-2 10:06:00
如何进入查找注册表的模式~~~
ぇ小心病毒ぇ - 2006-11-2 10:29:00
...没人知道吗
dy0406 - 2006-11-2 10:38:00
晕,查找注册表模式?
单击开始-运行,输入regedit,单击确定,进入注册表,单击编辑,看见查找没有?
ぇ小心病毒ぇ - 2006-11-2 10:55:00
我怎么找不到[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
以及
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[SDAgent Service / SDAgentService]
<C:\Program Files\Common Files\smartde\sde.exe><N/A>
??????????????
高歌猛进 - 2006-11-2 11:01:00
【我不是你的天使的贴子】在注册表删除:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
以及
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
[SDAgent Service / SDAgentService]
<C:\Program Files\Common Files\smartde\sde.exe><N/A>
从哪儿看出来的?
高歌猛进 - 2006-11-2 11:09:00
病毒名称路径?
修复:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<stdup><> [N/A]
ぇ小心病毒ぇ - 2006-11-2 11:11:00
我也不知道啊~~~上楼不是有位叫我怎么做的吗~~~~~~
之乎者也 - 2006-11-2 11:25:00
晕,不会是照搬过来的吧,我也看不到
ぇ小心病毒ぇ - 2006-11-2 12:19:00
你们看下我发的图~~~在说
ぇ小心病毒ぇ - 2006-11-2 12:21:00
| 引用: |
【ぇ小心病毒ぇ的贴子】你们看下我发的图~~~在说 ……………… |
附件:
7056272006112121319.BMP
ぇ小心病毒ぇ - 2006-11-2 12:56:00
没人有办法吗~~~
之乎者也 - 2006-11-2 13:01:00
"C:\WINDOWS\SYSTEM32\Userinit.exe,"后面还有东西吗
ぇ小心病毒ぇ - 2006-11-2 13:52:00
有啊
ぇ小心病毒ぇ - 2006-11-2 13:53:00
之乎者也 - 2006-11-2 14:55:00
ぇ小心病毒ぇ - 2006-11-2 15:27:00
C:\WINDOWS\system32\userinit.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
就这2个~~~他们说修复怎么修复和删除啊~~~~~~
之乎者也 - 2006-11-2 15:38:00
C:\WINDOWS\system32\userinit.exe这项没有问题,不用管它。
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<stdup><> [N/A]这个是流氓,直接用你扫描的工具在启动项里删除它。
ぇ小心病毒ぇ - 2006-11-2 15:57:00
大哥啊没问题...别吓我啊~~~
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
这就直接删了?????这不是系统文件吗
ぇ小心病毒ぇ - 2006-11-2 16:19:00
还在吗???
© 2000 - 2026 Rising Corp. Ltd.