瑞星卡卡安全论坛
组织部长 - 2006-12-11 19:44:00
昨天上网,中了病毒,通过杀毒软件和手动进行了查杀,但今天发现开机速度明显减慢,启动完后拨号上网,打开百度居然是有毒的,好像是被自动转接了。
打开C:\WINDOWS\system32\drivers\etc下的Hosts文件,内容如下:
127.0.0.1 localhost
58.215.74.70 www.hyap98.com
58.215.74.70 hyap98.com
58.215.74.70 guijuan.1.suhai.cn
58.215.74.70 baidu.com
58.215.74.70 www.baidu.com
明显中了木马,于是将
58.215.74.70 www.hyap98.com
58.215.74.70 hyap98.com
58.215.74.70 guijuan.1.suhai.cn
58.215.74.70 baidu.com
58.215.74.70 www.baidu.com
这5行删除,保存,重启,开机依然很慢,再次打开C:\WINDOWS\system32\drivers\etc下的Hosts文件,之前被删除的5行字再次出现,于是再次删除这5行,保存,重启,这次进入安全模式,打开C:\WINDOWS\system32\drivers\etc下的Hosts文件,没有出现被删除的这5行,再次重启进入正常模式,开机依旧很慢,再次打开C:\WINDOWS\system32\drivers\etc下的Hosts文件,那5行字又出现了!
哪位高人知道该怎样清除这木马?!
附件:
80202520061211193549.JPG
不懂就要问 - 2006-12-11 19:52:00
Trojan.DL.VBS.Agent.cgp
路径C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2J67096T\index[2].htm
组织部长 - 2006-12-11 19:53:00
该怎样清除,谢谢?
huigezi2006 - 2006-12-11 19:59:00
日志
组织部长 - 2006-12-11 20:03:00
不好意思,请问是什么的日志?
不懂就要问 - 2006-12-11 20:05:00
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2J67096T 有高手吗?问一下这个文件是干什么的?我的电脑里面这个文件里面有蛮多东西的.可以删除吗?
不懂就要问 - 2006-12-11 20:07:00
瑞星应该能杀
huigezi2006 - 2006-12-11 20:10:00
那是IE临时文件夹,清空!一些病毒藏在里面!
顺带告诉楼主
下载 System Repair Engineer,
http://www.kztechs.com/sreng/sreng2.zip
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
组织部长 - 2006-12-11 20:32:00
2006-12-11,20:16:56
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<ATIModeChange><Ati2mdxx.exe> [(Verified)ATI Technologies, Inc.]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<AGRSMMSG><AGRSMMSG.exe> [(Verified)Agere Systems]
<SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe> [(Verified)Synaptics, Inc.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Synaptics, Inc.]
<Q-HotkeyMgr><"C:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe"> [N/A]
<IMSCMIG40W><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log> [Microsoft Corporation]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<avast!><D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe> [(Verified)N/A]
<Look 'n' Stop><"D:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto> [Soft4Ever]
<!AVG Anti-Spyware><"D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [Anti-Malware Development a.s.]
<StormCodec_Helper><"D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<Realplayones><C:\WINDOWS\Realplayones.exe> [N/A]
<BIH><C:\WINDOWS\System32\rundll32.exe bih.dll, InitGauge> [Thomas Michel eMail: support.batteryinfo@arcor.de Web: http://www.batteryinfo.de.vu or http://home.arcor.de/batteryinfo]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\System32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<DLMon><> [N/A]
==================================
启动文件夹
N/A
==================================
服务
[avast! iAVS4 Control Service / aswUpdSv]
<"D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[avast! Antivirus / avast! Antivirus]
<"D:\Program Files\Alwil Software\Avast4\ashServ.exe"><N/A>
[avast! Mail Scanner / avast! Mail Scanner]
<"D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service><ALWIL Software>
[avast! Web Scanner / avast! Web Scanner]
<"D:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service><ALWIL Software>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard]
<D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[BlueSoleil Hid Service / BlueSoleil Hid Service]
<D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe><N/A>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
==================================
驱动程序
[avast! Asynchronous Virus Monitor / Aavmker4]
<C:\WINDOWS\SYSTEM32\DRIVERS\Aavmker4.SYS><ALWIL Software>
[aeaudio / aeaudio]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Agere Systems Soft Modem / AgereSoftModem]
<System32\DRIVERS\AGRSM.sys><Agere Systems>
[avast! Standard Shield Support / aswMon2]
<C:\WINDOWS\SYSTEM32\DRIVERS\aswMon2.SYS><ALWIL Software>
[aswRdr / aswRdr]
<C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.SYS><ALWIL Software>
[avast! Network Shield Support / aswTdi]
<C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.SYS><ALWIL Software>
[ati2mtag / ati2mtag]
<System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver]
<\??\D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[Bluetooth Audio Service / BlueletAudio]
<System32\DRIVERS\blueletaudio.sys><IVT Corporation>
[Bluetooth PAN Network Adapter / BT]
<System32\DRIVERS\btnetdrv.sys><IVT Corporation>
[Bluetooth USB For Bluetooth Service / Btcsrusb]
<System32\Drivers\btcusb.sys><IVT Corporation>
[Bluetooth HID Enumerator / BTHidEnum]
<System32\DRIVERS\vbtenum.sys><N/A>
[Bluetooth HID Manager Service / BTHidMgr]
<\SystemRoot\System32\Drivers\BTHidMgr.sys><IVT Corporation>
[Bluetooth Network Filter / BTNetFilter]
<\??\C:\WINDOWS\system32\drivers\BTNetFilter.sys><N/A>
[d347bus / d347bus]
<\SystemRoot\System32\DRIVERS\d347bus.sys><>
[d347prt / d347prt]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[Intel(R) PRO Adapter Driver / E100B]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[EMCR / EMCR]
<System32\DRIVERS\EMCR7SK.sys><ENE Technology Inc.>
[ENE Cardbus Patch Driver / ENECBPTH]
<C:\WINDOWS\SYSTEM32\DRIVERS\ENECBPTH.SYS><EnE Technology Inc.>
[lnsfw1 / lnsfw1]
<C:\WINDOWS\SYSTEM32\DRIVERS\lnsfw1.SYS><Soft4Ever>
[Netgroup Packet Filter / NPF]
<System32\DRIVERS\npf.sys><CACE Technologies>
[Direct Parallel Link Driver / Ptilink]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv]
<System32\DRIVERS\secdrv.sys><N/A>
[Look 'n' Stop Driver / SFilter]
<System32\DRIVERS\lnsfw.sys><Soft4Ever>
[SMC IrCC Miniport Device Driver / SMCIRDA]
<System32\DRIVERS\smcirda.sys><SMC>
[smwdm / smwdm]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[SVKP / SVKP]
<\??\C:\WINDOWS\System32\SVKP.sys><AntiCracking>
[Synaptics TouchPad Driver / SynTP]
<System32\DRIVERS\SynTP.sys><Synaptics, Inc.>
==================================
浏览器加载项
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <E:\software\Flashget\Flashget v1.65 Plus\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\System32\CMBEdit.dll, >
[CMBSafeHelper Class]
{26BCA338-BB94-4E8F-A082-3E5735875B79} <C:\WINDOWS\System32\CMBGUARD.dll, >
[Microsoft Chart Control 6.0 (SP4) (OLEDB)]
{3A2B370C-BA0A-11D1-B137-0000F8753F5D} <C:\WINDOWS\System32\MSCHRT20.OCX, Microsoft Corporation>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[PowerPlayer Control]
{5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\DOCUME~1\李勇\APPLIC~1\ppStream\100~1.139\POWERP~1.DLL, PPStream Inc.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[DigitalTrafic Control]
{7FC22A16-79E6-4787-9C96-B6359BB1106D} <C:\WINDOWS\DOWNLO~1\DIGITA~1.OCX, Broad-way>
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[SMI MapView Control]
{CA828031-4325-11D4-BDB2-00105A776E78} <C:\WINDOWS\Downloaded Program Files\SMIWMap.dll, 上海市测绘院基础地理信息中心, Shanghai Municipal Instatute of Surveying & Mapping,毕俊, 021-62549550-8122, bj@smi.stn.sh.cn>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[PBActiveX40 Control]
{F2EB8999-766E-4BF6-AAAD-188D398C0D0B} <C:\WINDOWS\System32\CMBPB40.ocx, China Merchants Bank>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<E:\software\Flashget\Flashget v1.65 Plus\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<E:\software\Flashget\Flashget v1.65 Plus\jc_all.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
组织部长 - 2006-12-11 20:35:00
==================================
正在运行的进程
[PID: 520][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1392][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1416][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
[PID: 1460][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1472][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1640][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1820][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[PID: 2024][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 248][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 916][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\bih.dll] [Thomas Michel eMail: support.batteryinfo@arcor.de Web: http://www.batteryinfo.de.vu or http://home.arcor.de/batteryinfo, 1, 2, 0, 25]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49]
[D:\Program Files\Alwil Software\Avast4\ashShell.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\ffdshow.ax] [N/A, 1.0.2.2028]
[D:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll] [Gabest, 1, 0, 1, 3]
[D:\Program Files\Ringz Studio\Storm Codec\Codecs\PmpSplt.ax] [cooleyes, 1, 0, 0, 8]
[D:\Program Files\Ringz Studio\Storm Codec\Codecs\RMSplt.ax] [Gabest, 1, 0, 1, 1]
[D:\Program Files\Ringz Studio\Storm Codec\Codecs\TTL2Dec.dll] [N/A, N/A]
[D:\Program Files\Ringz Studio\Storm Codec\Codecs\Vid1Dec.dll] [N/A, N/A]
[PID: 932][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.1699 (xpsp2.050610-1533)]
[PID: 1324][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] [ATI Technologies, Inc., 6.14.10.5021]
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS] [ATI Technologies, Inc., 6.14.10.5021]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] [ATI Technologies, Inc., 6.14.10.5021]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] [ATI Technologies, Inc., 6.14.10.5021]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[PID: 1332][C:\WINDOWS\AGRSMMSG.exe] [Agere Systems, 2.1.25 2.1.25 02/14/2003 11:58:58]
[PID: 1340][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe] [Synaptics, Inc., 7.5.5 24Apr03]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[PID: 1352][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 7.5.5 24Apr03]
[C:\WINDOWS\System32\SynCOM.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[C:\WINDOWS\System32\SynTPAPI.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[PID: 188][C:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe] [, 1, 0, 0, 13]
[C:\Program Files\BenQ\Q-HotkeyMgr\HKSensor.DLL] [N/A, N/A]
[C:\Program Files\BenQ\Q-HotkeyMgr\dhpolywin.dll] [N/A, N/A]
[C:\Program Files\BenQ\Q-HotkeyMgr\ACPIDrvDLL.dll] [, 1, 0, 0, 1]
[PID: 1376][D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe] [N/A, 5, 0, 0, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ChineseS\Base.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ChineseS\Lang.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[d:\program files\alwil software\avast4\ahruimai.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashUInt.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\XT1922.dll] [Codejock Software, 1, 9, 4, 0]
[d:\program files\alwil software\avast4\ahruimes.dll] [ALWIL Software, 4, 7, 889, 0]
[d:\program files\alwil software\avast4\ahruins.dll] [ALWIL Software, 4, 7, 889, 0]
[d:\program files\alwil software\avast4\ahruiout.dll] [ALWIL Software, 4, 7, 889, 0]
[d:\program files\alwil software\avast4\ahruip2p.dll] [ALWIL Software, 4, 7, 889, 0]
[d:\program files\alwil software\avast4\ahruistd.dll] [ALWIL Software, 4, 7, 889, 0]
[d:\program files\alwil software\avast4\ahruiws.dll] [ALWIL Software, 4, 7, 889, 0]
[d:\program files\alwil software\avast4\ahruijs.dll] [N/A, 4, 7, 889, 0]
[PID: 1532][D:\Program Files\Soft4Ever\looknstop\looknstop.exe] [Soft4Ever, 2, 0, 0, 5]
[C:\WINDOWS\System32\fwapi.dll] [Soft4Ever, 4.01]
[D:\Program Files\Soft4Ever\looknstop\plugin_language.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[PID: 1476][D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[PID: 1748][C:\WINDOWS\System32\rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\bih.dll] [Thomas Michel eMail: support.batteryinfo@arcor.de Web: http://www.batteryinfo.de.vu or http://home.arcor.de/batteryinfo, 1, 2, 0, 25]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[PID: 1756][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[PID: 1664][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1740][D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe] [N/A, N/A]
[D:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[PID: 1776][C:\WINDOWS\System32\Ati2evxx.exe] [N/A, N/A]
[PID: 1796][D:\Program Files\Alwil Software\Avast4\ashServ.exe] [N/A, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswAux.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswEngin.dll] [ALWIL Software, 4, 7, 892, 0]
[D:\Program Files\Alwil Software\Avast4\aswScan.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashBase.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashTask.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswInteg.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswIdle.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\Aavm4h.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ChineseS\Base.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\UNACEV2.DLL] [N/A, N/A]
[D:\Program Files\Alwil Software\Avast4\AhResMai.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ahResMes.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\AhResNS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\AhResOut.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ahResP2P.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\AhResStd.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\AhResWS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\AhResJs.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashSSqlt.dll] [ALWIL Software, 4, 6, 763, 0]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
组织部长 - 2006-12-11 20:35:00
[PID: 1868][D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe] [N/A, N/A]
[PID: 1952][C:\WINDOWS\System32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2724][D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashUInt.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashBase.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\XT1922.dll] [Codejock Software, 1, 9, 4, 0]
[D:\Program Files\Alwil Software\Avast4\Aavm4h.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashTask.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswAux.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\AhResMai.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ChineseS\Base.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswEngin.dll] [ALWIL Software, 4, 7, 892, 0]
[D:\Program Files\Alwil Software\Avast4\aswScan.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ChineseS\Lang.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ChineseS\langmai.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[PID: 3156][D:\Program Files\Alwil Software\Avast4\ashWebSv.exe] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashBase.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\Aavm4h.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashTask.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswAux.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ChineseS\Base.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\ashWsFtr.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswScan.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\AhResWs.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\Program Files\Alwil Software\Avast4\aswEngin.dll] [ALWIL Software, 4, 7, 892, 0]
[PID: 2156][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[D:\Program Files\Tencent\QQ\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
[D:\Program Files\Alwil Software\Avast4\AhAScr.dll] [ALWIL Software, 4, 7, 892, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 3720][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2052][E:\software\BitComet\BitComet_0.60\BitComet.exe] [www.BitComet.com, 0.60.]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[D:\Program Files\Alwil Software\Avast4\AhAScr.dll] [ALWIL Software, 4, 7, 892, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 3060][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
[D:\Program Files\Tencent\QQ\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
[D:\Program Files\Alwil Software\Avast4\AhAScr.dll] [ALWIL Software, 4, 7, 892, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll] [ALWIL Software, 4, 7, 889, 0]
[D:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 2140][D:\Downloads\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll] [ALWIL Software, 4, 7, 889, 0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.5.5 24Apr03]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
我现在开机后就把那5行字删除了,所以日志中最后一行只有
127.0.0.1 localhost
一项
huigezi2006 - 2006-12-11 20:40:00
清空IE临时文件夹和关闭系统还原
先用任务管理器看有没有Realplayones进程,如有,结束再
运行System Repair Engineer 启动项目,注册表,删除
<Realplayones><C:\WINDOWS\Realplayones.exe> [N/A]
重启按F8进入安全模式,
我的电脑,工具,文件夹选项,查看,显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉删除删除上述文件!
组织部长 - 2006-12-11 20:49:00
有Realplayones着一项,而且还有一项是DLMon,见下图,蓝色字体的,这个是什么呢?
Realplayones又是什么呢?
附件:
80202520061211204023.JPG
组织部长 - 2006-12-11 21:25:00
有Realplayones着一项,而且还有一项是DLMon,见下图,蓝色字体的,这个是什么呢?
Realplayones又是什么呢?
红夜鬼1 - 2006-12-11 21:34:00
.
组织部长 - 2006-12-11 21:39:00
BIH是我本本的一个电池管理软件,也要删除吗?
红夜鬼1 - 2006-12-11 21:42:00
下载个超级兔子,清理一下,IE临时文件
组织部长 - 2006-12-11 21:44:00
那5行字已经没有出现了,但启动依旧很慢,不知道为什么!
组织部长 - 2006-12-11 21:45:00
组织部长 - 2006-12-11 21:45:00
那5行字已经没有出现了,但启动依旧很慢,不知道为什么!
红夜鬼1 - 2006-12-11 22:03:00
打个比方,一个文件夹里没有文件
组织部长 - 2006-12-11 22:57:00
DLMon是什么?
组织部长 - 2006-12-12 9:07:00
DLMon是什么?
组织部长 - 2006-12-12 15:19:00
DLMon是什么?
1
© 2000 - 2026 Rising Corp. Ltd.