kangtajtl888 - 2006-12-25 0:57:00
文件: C:\WINDOWS\uninstall\rundl13
中了这个木马为什么整个硬盘可执行文件EXE全都不行了,一进任何一个文件夹里有EXE的文件,就给卡巴删了,大家要帮帮我呀
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\Ringz Studio\mplayerc.exe 5 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\AOA\unins000.exe 699.4 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\AOA\OptimizePkgSys.exe 282.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\AOA\AOA.exe 1.7 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\AOA\AOA\core.exe 98.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\Program Files\Optic\神泣\Updater.exe 1.8 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc d:\tuneup utilities 2006\integrator.exe 337.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc d:\tuneup utilities 2006\keygen.exe 537.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc d:\tuneup utilities 2006\uninst.exe 116.8 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\Real\RealPlayer\realplay.exe 258.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\WinRAR\WinRAR.exe 447.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\WINISO53.EXE 816 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\Windows 流氓软件清理大师.exe 3.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\Winamp_5.08e_Pro_SC_Plus.exe 8.9 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\tu.exe 4.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\thunder5.0.3.86.exe 2.6 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\RealPlayer10-5GOLD_cn.exe 11.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\PrimoSetup.exe 10.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\MSJavaVM.exe 5.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\MP10Setup_skycn.exe 12.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\klcodec243f.exe 10 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\HelloNet_setup.exe 4.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\HA-TuneUp Utilities 2006-RCH.exe 6.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\HAP_WinRAR350B51Reg_LBJ.exe 1.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\DFX_7.2_for_Winamp_SC.exe 676.4 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\bsv2.8.0.065.EN.exe 4.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\BitComet_0.57.exe 1.7 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\6.exe 556.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\Ghost\GhostExp.exe 838.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\Ghost\Ghost32.exe 2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\Ghost\Ghost.exe 1.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\Winamp\Winamp.exe 1014.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\浩方对战平台\GameClient.exe 1.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\QQ\QQ.EXE 1.4 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\软件\FastAIT2007_2\2006-12-07\setup.exe 3.7 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\Ringz Studio\StormSet.exe 347.8 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\Ringz Studio\uninst6.04.08.exe 134.9 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\KuGoo3\KuGoo.exe 7.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe 4.1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\Intel\Intel Application Accelerator\intelata.exe 606.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\DNA-drivers\Temporal_Tool\ATITemporalAASwitch.exe 198.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\DNA-drivers\ATITrayTools\atitray.exe 1 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\Warcraft III\worldedit.exe 4.2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\Warcraft III\World Editor.exe 114.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\Warcraft III\Warcraft III.exe 326.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\Warcraft III\War3.exe 1.6 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc F:\Warcraft III\Frozen Throne.exe 326.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\Dreamweaver MX官方中文版\Setup.exe 222.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\绿色工具\NvCoolFX2.2.exe 158.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\绿色工具\IEcq修复.exe 798 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\uninstall.exe 78.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\CS!\cstrike.exe 982.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\CS!\voice_tweak.exe 230.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\CS!\UNWISE.EXE 204.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\CS!\SierraUp.exe 514.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\CS!\opforup.exe 1.9 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\CS!\hltv.exe 346.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\CS\CS!\hlds.exe 134.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc E:\DIABLO II\BNUpdate.exe 246.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\WINDOWS\Logo1_.exe 58.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\Shredder.exe 141.9 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\K-Lite Codec Pack\unins000.exe 850.5 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\StartUpManager.exe 241.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\SystemControl.exe 128.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\Undelete.exe 217.3 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\SystemInformation.exe 480.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\SystemOptimizer.exe 440.1 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\UpdateWizard.exe 187.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\WinStylerThemeSvc.exe 173.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\WinStyler.exe 829.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\DiskCleaner.exe 280.0 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\MemOptimizer.exe 345.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\OneClickMaintenance.exe 102.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\PMLauncher.exe 67.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\ProcessManager.exe 269.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\RegistryCleaner.exe 404 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\RegistryDefrag.exe 163.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\RegistryDefragHelper.exe 67.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\RegistryEditor.exe 288.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\RescueCenter.exe 188.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\SilentUpdater.exe 131.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\TuneUp Utilities 2006\access.exe 82.7 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\WinPcap\npf_mgm.exe 106.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\WinPcap\daemon_mgm.exe 106.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\WinPcap\rpcapd.exe 134.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\Program Files\ATI Technologies\ATI Control Panel\atiprbxx.exe 178.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\X-Scan\xscan_gui.exe 1.8 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\X-Scan\Update.exe 856.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\WINDOWS\uninstall\rundl132.exe 58.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\BitComet\BitComet.exe 3.3 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc C:\program files\ati technologies\ati control panel\atiptaxx.exe 394.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\Ghost\Ghost32.exe 2 MB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\Winamp\winampa.exe 91.2 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\Winamp\undfx70.exe 101.8 KB
感染: 木马程序 Trojan-PSW.Win32.Magania.lc D:\Thunder\Thunder.exe 98.2 KB
鸟儿天上飞 - 2006-12-25 1:01:00
请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。
下载地址
http://www.kztechs.com/sreng/sreng2.zip
kangtajtl888 - 2006-12-25 1:06:00
[CODE]
2006-12-25,00:55:10
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
<ATIModeChange><; Ati2mdxx.exe> [ATI Technologies, Inc.]
<ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [N/A]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<load><; C:\WINDOWS\uninstall\rundl132.exe> [N/A]
<ltnward><; C:\WINDOWS\system32\ltnward.exe> [N/A]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<StormCodec_Helper><; "C:\Program Files\Ringz Studio\StormSet.exe" /S /opti> [N/A]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
==================================
启动文件夹
N/A
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Disabled]
<C:\WINDOWS\system32\ati2sgag.exe><>
[卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Disabled]
<"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[IdeBusDr / IdeBusDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
[Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><Politecnico di Torino>
[p2pfilter / p2pfilter][Stopped/Manual Start]
<\??\C:\Program Files\NetSoft\P2POver\p2pfilter.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
kangtajtl888 - 2006-12-25 1:07:00
==================================
浏览器加载项
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Yahoo! Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[VnetAnprIns Class]
{74447F9C-5691-4A9A-8BE4-564092E40B03} <C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VnetAnprIns Class]
{74447F9C-5691-4A9A-8BE4-564092E40B03} <C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Yahoo! Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, N/A>
[上传到QQ网络硬盘]
<D:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\KUGOO3\KuGoo3DownX.htm, N/A>
[添加到QQ自定义面板]
<D:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 492][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4109]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 624][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 636][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 880][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 932][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1724][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1944][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 348][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[d:\TuneUp Utilities 2006\sdshelex.dll] [TuneUp Software GmbH, 1.0.0.253]
[d:\TuneUp Utilities 2006\rtl60.bpl] [Borland Software Corporation, 6.0.6.241]
[d:\TuneUp Utilities 2006\vcl60.bpl] [Borland Software Corporation, 6.0.6.240]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 956][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 440][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 1004][C:\DOCUME~1\SaGa\LOCALS~1\Temp\sreng2.zip 的临时目录 1\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[PID: 812][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW
==================================
[/CODE]
kangtajtl888 - 2006-12-25 1:08:00
快点看看怎么会事
鸟儿天上飞 - 2006-12-25 1:12:00
http://forum.ikaka.com/topic.asp?board=28&artid=8235241用这个杀 杀的时候注意把卡巴关掉 要不你的EXE 会全部牺牲的
多杀几次 在扫描一次日志 我一晚上都在
kangtajtl888 - 2006-12-25 1:30:00
现在可以了,顶!之前删了一下EXE问题!
这个病毒真TMD叼!
谢谢楼上!
不知重启会不会在出现!
kangtajtl888 - 2006-12-25 1:38:00
计算机重启后删除: 木马程序 Trojan-PSW.Win32.OnLineGames.bs文件: C:\DOCUME~1\SaGa\LOCALS~1\Temp\rxzs.dll
这个怎样杀呀!!!!!!!!!!
顶重启还有!!!
鸟儿天上飞 - 2006-12-25 1:42:00
日志
© 2000 - 2026 Rising Corp. Ltd.