瑞星卡卡安全论坛
秋风明明 - 2006-11-15 17:14:00
另外还有好多啊,都说是WINDOWS下的PE病毒啊,每次杀了后重又有毒,有些就是要手动删啊,删了又有啊,高手们请看我的日志啊
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation]
<a6b6edb36a5ac12e3c648924c3c698b4><; "D:\下\d120jx210.12012.0.exe" -t 12012.0> [N/A]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [Microsoft Corporation]
<MsnMsgr><; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background> [N/A]
<Super Rabbit Desktop Search><; ; D:\Program Files\Super Rabbit\新建文件夹\srsearch.exe> [N/A]
<Super Rabbit IEPro><D:\Program Files\Super Rabbit\新建文件夹\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
<Yahoo! Pager><; > [N/A]
<<DLMon>><<>[]> [N/A]
<<ipsec>><<rundll32.exe>[]> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<CHK><C:\Program Files\isofti corp\BSC宽带支撑系统\checkbsc.exe> [N/A]
<BigDogPath><; C:\WINDOWS\VM_STI.EXE USB PC Camera 301P> [N/A]
<iDuba Personal FireWall><; > [N/A]
<IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<ISC><; > [N/A]
<ISC_UpDate><; > [N/A]
<KAVRun><; > [N/A]
<KpopMon><; > [N/A]
<Kulansyn><; > [N/A]
<PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<RfwMain><; "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<SoundMan><; SOUNDMAN.EXE> [N/A]
<SysExplr><; > [N/A]
<WDM><; MSWDM.EXE> [N/A]
<BWC><C:\Program Files\isofti corp\BSC宽带支撑系统\upgrade.exe> [N/A]
<Search_hongjie><> [N/A]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<Services><C:\prosys32.exe> [N/A]
<helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<WDM><; MSWDM.EXE> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><c:\windows\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll> [北京三七二一科技有限公司]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{9A36CEDC-2619-43F0-8108-50A321AD3057}><C:\WINDOWS\System32\qomnlki.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomnlki]
<WinlogonNotify: qomnlki><qomnlki.dll> [N/A]
秋风明明 - 2006-11-15 17:15:00
启动文件夹
N/A
==================================
服务
[C-DillaSrv / C-DillaSrv]
<C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE><C-Dilla Ltd>
[Canon NetSpot Suite Service / Canon NetSpot Suite Service]
<C:\Program Files\Canon\VDC\AuVdc.exe><CANON INC.>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IMAPI CD-Burning COM Service / ImapiService]
<C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[Rising Proxy Service / RfwProxySrv]
<d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
<d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
<"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><NetGroup - Politecnico di Torino>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[WINLASS / WINLASS]
<><N/A>
==================================
驱动程序
[468623 / 468623]
<\SystemRoot\System32\drivers\468623.sys><N/A>
[a0 / a0]
<\SystemRoot\\SystemRoot\System32\drivers\468623.sys><N/A>
[Service for Avance AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><N/A>
[ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter / AN983]
<System32\DRIVERS\AN983.sys><ADMtek Incorporated.>
[ati2mpaa / ati2mpaa]
<System32\DRIVERS\ati2mpaa.sys><ATI Technologies Inc.>
[atimtag / atimtag]
<System32\DRIVERS\atimtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[C-Dilla / C-Dilla]
<\??\C:\WINDOWS\System32\drivers\CDANT.SYS><Macrovision>
[CnsMinKP / CnsMinKP]
<\SystemRoot\System32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[Intel(R) PRO Adapter Driver / E100B]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[ExpScaner / ExpScaner]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
<\??\D:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[MEMSCAN / MEMSCAN]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
<\??\d:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[NetGroup Packet Filter Driver / NPF]
<system32\drivers\npf.sys><Politecnico di Torino>
[npkcrypt / npkcrypt]
<\??\D:\Tencent\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv]
<\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[S3Psddr / S3Psddr]
<System32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
[Secdrv / Secdrv]
<System32\DRIVERS\secdrv.sys><N/A>
[SKNFW / SKNFW]
<\??\C:\WINDOWS\System32\Drivers\SKNFW.sys><N/A>
[Sparrow / Sparrow]
<\SystemRoot\System32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[VIA AGP Filter / viaagp1]
<\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[ViaIde / ViaIde]
<\SystemRoot\System32\DRIVERS\viaidexp.sys><VIA Technologies, Inc.>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio]
<system32\drivers\viaudios.sys><VIA Technologies, Inc.>
秋风明明 - 2006-11-15 17:16:00
==================================
浏览器加载项
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\Super Rabbit\新建文件夹\haokanbar.dll, Xiang Feng Technology>
[BandIE Class]
{77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.>
[]
{9A36CEDC-2619-43F0-8108-50A321AD3057} <C:\WINDOWS\System32\qomnlki.dll, N/A>
[CnsHook Class]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[Yahoo 3.5G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[名品折扣]
{59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[雅虎WIDGET]
{6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Tencent\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Tencent\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[金山毒霸]
{A9BE2902-C447-420A-BB7F-A5DE921E6138} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\Super Rabbit\新建文件夹\haokanbar.dll, Xiang Feng Technology>
[WebActivater Control]
{3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINDOWS\System32\WEBACT~1.OCX, QQ>
[YupIEBarExtObj Class]
{8811D177-42CE-4438-B7D4-38F6A4F1D327} <C:\WINDOWS\Downloaded Program Files\YupIEBarExt3.dll, >
[Qzone Media Tools]
{AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} <D:\Tencent\VQQPLA~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[My99Launch Control]
{D57A1919-CB3C-461C-8F34-A87A1CD9127E} <C:\WINDOWS\System32\99Launch.ocx, >
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
<, N/A>
[&使用迅雷下载全部链接]
<, N/A>
[上传到QQ网络硬盘]
<D:\Tencent\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\Tencent\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Tencent\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<, N/A>
秋风明明 - 2006-11-15 17:18:00
正在运行的进程
[PID: 500][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\qomnlki.dll] [N/A, N/A]
[PID: 624][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 636][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 796][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 844][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 876][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1032][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1048][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1072][C:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 1, 47]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 18, 1, 0, 12]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 33]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\HookWeb.dll] [rising, 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\MailMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 35]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 32]
[C:\Program Files\Rising\Rav\RSUnpack.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 20]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[PID: 1116][d:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 30]
[d:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 12]
[d:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 6]
[d:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 21]
[d:\program files\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[d:\program files\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 9]
[PID: 1336][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\system32\AUCJLMNT.DLL] [CANON INC., 5.0.0.4]
[C:\WINDOWS\system32\NBLMC.DLL] [CANON INC., 7.0.0.0]
[C:\Program Files\Canon\VDCP\AuSpMsngr.dll] [CANON INC., 3, 0, 0, 0]
[PID: 1472][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1548][C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE] [C-Dilla Ltd, 3.24.010]
[PID: 1572][C:\Program Files\Canon\VDC\AuVdc.exe] [CANON INC., 3, 0, 0, 2]
秋风明明 - 2006-11-15 17:21:00
[C:\Program Files\Canon\VDC\AuSrvc.dll] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AUPAM.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuPMPublisher.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuIpc.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuCrSpMsngr.crp] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuPaSnmp.dll] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuSnmp.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuTrans.dll] [CANON INC., 3, 1, 1, 0]
[C:\Program Files\Canon\VDC\AUOIM.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuPaCpca.dll] [CANON INC., 3, 1, 0, 1]
[C:\Program Files\Canon\VDC\aucpca.dll] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuPaCjl.dll] [CANON INC., 3, 1, 0, 1]
[C:\Program Files\Canon\VDC\AUCJLPRS.dll] [CANON INC., 2, 5, 0, 1]
[C:\Program Files\Canon\VDC\AuPaPjl.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuLocalt.dll] [CANON INC., 2, 4, 0, 0]
[C:\Program Files\Canon\VDC\AUSS.dll] [CANON INC., 3, 0, 0, 0]
[C:\WINDOWS\System32\NBLocalt.dll] [CANON INC., 5, 5, 0, 1]
[C:\WINDOWS\System32\NBcbtNT.dll] [CANON INC., 5, 5, 0, 1]
[C:\Program Files\Canon\VDC\NsCanon.oim] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\Ns1213.oim] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\NsAT.oim] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\NsCIS.oim] [CANON INC., 1, 1, 0, 0]
[C:\Program Files\Canon\VDC\NsHR.oim] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\NsPRT.oim] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\NsTR.oim] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuDifDevInfoS.dif] [CANON INC., 1, 2, 0, 0]
[C:\Program Files\Canon\VDC\AuDifDevInfo.dll] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuPSCommonS.dll] [CANON INC., 3, 1, 0, 1]
[C:\Program Files\Canon\VDC\AuAE.dll] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuDifEventS.dif] [CANON INC., 1, 2, 0, 0]
[C:\Program Files\Canon\VDC\AUDIFEVENT.dll] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuDifNbS.dif] [CANON INC., 2, 5, 0, 0]
[C:\Program Files\Canon\VDC\AUDIFNB.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AUDIFSYSCON.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuDifSS.dif] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuDifSysconS.dif] [CANON INC., 2, 5, 0, 0]
[C:\Program Files\Canon\VDC\AuDscvrS.dif] [CANON INC., 1, 2, 0, 0]
[C:\Program Files\Canon\VDC\AUDSCVR.dll] [CANON INC., 3, 1, 0, 2]
[C:\Program Files\Canon\VDC\AuKeeperS.dif] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AUKEEPER.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuSnmpDifS.dif] [CANON INC., 1, 2, 0, 0]
[C:\Program Files\Canon\VDC\AuFscAccS.fsc] [CANON INC., 2, 5, 0, 1]
[C:\Program Files\Canon\VDC\AUFSCACC.dll] [CANON INC., 3, 1, 0, 1]
[C:\Program Files\Canon\VDC\AuFscDevMgmtS.fsc] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuFscDevMgmt.dll] [CANON INC., 1, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuFscResMgmtS.fsc] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuFscResMgmt.dll] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuPauResTool.dll] [CANON INC.\, 1, 2, 0, 0]
[C:\Program Files\Canon\VDC\AuFscLogS.fsc] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuFscLog.dll] [CANON INC., 3, 0, 0, 0]
[C:\Program Files\Canon\VDC\AuDHLmk.ndh] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuDHSIP.ndh] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuDHSIPX.ndh] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuDHEml.ndh] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuDHIP.ndh] [CANON INC., 3, 1, 0, 0]
[C:\Program Files\Canon\VDC\AuDHIPX.ndh] [CANON INC., 3, 1, 0, 0]
[PID: 1656][C:\WINDOWS\System32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1980][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 1, 0, 4, 2]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[C:\WINDOWS\System32\qomnlki.dll] [N/A, N/A]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001]
[C:\PROGRA~1\3721\AutoLive.dll] [, 1, 1, 8, 1327]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\PROGRA~1\baidu\bar\baidubar.dll] [Baidu.com, Inc., 2, 0, 2, 114]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[d:\PROGRA~1\3721\ske\contmenu.dll] [N/A, N/A]
[C:\WINDOWS\System32\JPWB.IME] [常诚研制, 4.00.950]
[PID: 2024][d:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 48]
[d:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
[d:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[d:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 252][C:\WINDOWS\System32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\WINDOWS\DOWNLO~1\cnsio.dll] [北京三七二一科技有限公司, 1, 0, 2, 8]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[C:\WINDOWS\DOWNLO~1\CnsMinEx.dll] [国风因特软件(北京)有限公司, 1, 0, 3, 5]
[PID: 296][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 344][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3292]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 676][C:\Program Files\isofti corp\BSC宽带支撑系统\checkbsc.exe] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 956][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 968][C:\prosys32.exe] [N/A, N/A]
[PID: 1024][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 1, 39]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[PID: 1096][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[C:\PROGRA~1\3721\AutoLive.dll] [, 1, 1, 8, 1327]
[C:\PROGRA~1\3721\notifier.dll] [, 1, 0, 0, 5]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[PID: 1364][C:\Program Files\isofti corp\BSC宽带支撑系统\bwc.exe] [宏杰软件开发有限公司, 2, 1, 9, 1]
[C:\WINDOWS\System32\wpcap.dll] [Politecnico di Torino, 3, 0, 0, 19]
[C:\WINDOWS\System32\packet.dll] [Politecnico di Torino, 3, 0, 0, 19]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 2544][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
秋风明明 - 2006-11-15 17:21:00
[PID: 120][D:\金信话吧管理专家\Jxsg2003.exe] [湖南娄底金信电子科技发展有限公限, 1.0.0.0]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[C:\Program Files\Common Files\Borland Shared\BDE\IDAPI32.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Borland Shared\BDE\IDR20009.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Borland Shared\BDE\BANTAM.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Borland Shared\BDE\IDPDX32.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Borland Shared\BDE\idsql32.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Borland Shared\BDE\idbat32.DLL] [N/A, N/A]
[PID: 3772][C:\Program Files\Rising\Rav\Rav.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 75]
[C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavUI.Dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 65]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 33]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\RavUIMsg.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 27]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\MVEngine.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
[C:\Program Files\Rising\Rav\Engine.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 35]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 32]
[C:\Program Files\Rising\Rav\RSUnpack.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 20]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\ExtMail.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 1, 0, 4, 2]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[C:\WINDOWS\System32\qomnlki.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 3020][D:\下\网络电视\陈\SREng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 0, 1325]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
6981313 - 2006-11-15 17:32:00
打开SRENG-启动项目-注册表,删除:
<Services><C:\prosys32.exe> [N/A]
打开SRENG-启动项目-驱动,选择隐藏微软的驱动,找到并删除:
[[468623 / 468623]
<\SystemRoot\System32\drivers\468623.sys><N/A>
[a0 / a0]
<\SystemRoot\\SystemRoot\System32\drivers\468623.sys><N/A>
安全模式下删除:
][C:\prosys32.exe] [N/A, N/A]
<\SystemRoot\System32\drivers\468623.sys><N/A>
<\SystemRoot\\SystemRoot\System32\drivers\468623.sys><N/A>
秋风明明 - 2006-11-15 18:20:00
按你的做了,重启后还有病毒啊Trojan.Vundo.w Trojan.DL.Agent.amb
1
© 2000 - 2026 Rising Corp. Ltd.