szlilong - 2007-1-13 14:32:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)Microsoft Corporation]
<svcshare><C:\WINNT\System32\drivers\spoclsv.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Corporation]
<PRONoMgrWired><C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe> [Intel(R) Corporation]
<RaidTool><C:\Program Files\VIA\RAID\raid_tool.exe> [VIA Technologies]
<NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize> [N/A]
<nwiz><nwiz.exe /install> [(Verified)NVIDIA Corporation]
<CnsMin><Rundll32.exe C:\WINNT\DOWNLO~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<xBarUpdate><C:\Program Files\xBar\xBarUpdate.exe> [N/A]
<TopDomainTDHelper><C:\WINNT\System32\TDHelp32.exe> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<图书馆管理系统服务器><d:\books\tlbk_svr\scktsrvr.exe> [N/A]
<Thunder><"D:\Program Files\Thunder Network\Thunder\Thunder.exe" /s> [Thunder Networking Technologies,LTD]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<2bqtsqw8vhs5><C:\WINNT\iexpiore.exe> [N/A]
<cu><C:\WINNT\winlog0n.exe> [N/A]
<Alitalk><C:\PROGRA~1\阿里巴巴\贸易通\AliTalk.EXE> [Alibaba]
<tmlurl><C:\WINNT\System32\ergaon.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<xBar><"C:\Program Files\xBar\update.exe"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINNT\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINNT\DOWNLO~1\CnsHook.dll> [北京三七二一科技有限公司]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINNT\System32\频道屏~1.SCR> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[服务管理器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\服务管理器.lnk --> C:\PROGRA~1\MICROS~3\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><N>
==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><N/A>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Dmsarrytps / Dmsarrytps][Stopped/Manual Start]
<><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[Intel NCS NetService / NetSvc][Stopped/Manual Start]
<C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe><Intel(R) Corporation>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Auto Start]
<C:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
[Siamrert / Siamrert][Stopped/Manual Start]
<><N/A>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
<d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\System32\mspmsnsv.dll><Microsoft Corporation>
szlilong - 2007-1-13 14:33:00
驱动程序
[1253781 / 1253781][Running/Boot Start]
<\SystemRoot\System32\drivers\1253781.sys><N/A>
[a0 / a0][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\1253781.sys><N/A>
[USB 2.0 (FS) ADFU Device / AdfuUd][Stopped/Manual Start]
<System32\Drivers\AdfuUd.sys><>
[ADProt / ADProt][Running/System Start]
<system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CnsMinKP / CnsMinKP][Running/Boot Start]
<\SystemRoot\System32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Intel(R) PRO/1000 Network Connection Driver / E1000][Running/Manual Start]
<System32\DRIVERS\e1000nt5.sys><Intel Corporation>
[epffurg / epffurg][Running/Boot Start]
<\SystemRoot\system32\drivers\epffurg.sys><>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[hardlock / hardlock][Running/Auto Start]
<\??\C:\WINNT\System32\drivers\hardlock.sys><Aladdin Knowledge Systems>
[Haspnt / Haspnt][Running/Auto Start]
<\??\C:\WINNT\System32\drivers\Haspnt.sys><Aladdin Knowledge Systems>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
<\??\D:\PROGRAM FILES\RISING\RAV\HookApi.Sys><瑞星软件有限公司>
[HookCont / HookCont][Running/Auto Start]
<\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
[nv / nv][Running/Manual Start]
<System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Feitian ROCKEY4 Device Service / ROCKEYNT][Running/Manual Start]
<System32\DRIVERS\Rockey4.sys><Feitian Technologies Co., Ltd.>
[senfilt / senfilt][Running/Manual Start]
<system32\drivers\senfilt.sys><Sensaura>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[TDVideo / TDVideo][Running/System Start]
<\??\C:\WINNT\System32\Drivers\TDVideo.sys><Nanjing Universal Networks (U-NET) Co., LTD.>
[VIA AGP Filter / viaagp1][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[viamraid / viamraid][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[VIA USB Host Controller Lower Filter / vulfnths][Running/Manual Start]
<\SystemRoot\System32\Drivers\vulfnth.sys><VIA Technologies, Inc.>
[VIA USB Roothub Lower Filter / vulfntrs][Running/Manual Start]
<\SystemRoot\System32\Drivers\vulfntr.sys><VIA Technologies, Inc.>
==================================
浏览器加载项
[Thunder Browser Helper]
{0C7C23EE-A848-485B-873C-0ED954731014} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll, Thunder Networking Technologies,LTD>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[CMoveCatchPic Object]
{0CF098A0-CBAC-4EFB-8451-3AFC201C7222} <C:\Program Files\xBar\xBarHelper.dll, N/A>
[Eye Class]
{41BE3A3D-6E4B-43F4-AAEB-5B4E95971968} <C:\WINNT\System32\iodbzfex.dll, >
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINNT\System32\ssup.dll, TENCENT>
[MAngle Class]
{9A556B8F-FD02-420E-A1FD-9DB33808254E} <C:\Program Files\MySec\secmouseaai.dll, SemeanKitty's Office>
[BhoObj Class]
{9C7BC48C-6EE7-43C4-A931-91F8DE3CD0D0} <C:\WINNT\System32\cuhqndbc.dll, >
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[CnsHook Class]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINNT\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <d:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[My 网蜜(&M)]
{102293E4-758B-4483-946B-714EBCEC91B8} <C:\Program Files\MySec\secbaraai.dll, SemeanKitty's Office>
[Yahoo 3.5G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[名品折扣]
{59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[雅虎WIDGET]
{6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[My 网蜜(&M)]
{102293E4-758B-4483-946B-714EBCEC91B8} <C:\Program Files\MySec\secbaraai.dll, SemeanKitty's Office>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\System32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[InfoCheck Class]
{F91BA567-79B9-467E-BC97-5DBA01BBC5EE} <C:\PROGRA~1\阿里巴巴\贸易通\Ali_Check.dll, >
[InstallCheck Class]
{FFB8C97E-39D4-4E8A-9FE4-B451A0D6CA65} <C:\PROGRA~1\阿里巴巴\贸易通\Ali_Check.dll, >
[!直接打开链接]
<res://C:\Program Files\MySec\secmouseaai.dll/seopenurl.html, N/A>
[&使用迅雷下载]
<D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<D:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[使用百度搜索]
<res://C:\Program Files\MySec\secmouseaai.dll/sesch_bd.html, N/A>
[加入365MY收藏夹(&U)]
<http://www.365my.com/rclick/add_url.php, N/A>
[加入365MY网摘(&N)]
<http://www.365my.com/rclick/add_net.php, N/A>
[发送到手机]
<C:\Program Files\xBar\xBar.htm, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
szlilong - 2007-1-13 14:33:00
正在运行的进程
[PID: 148][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2170.1]
[PID: 180][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2137.1]
[PID: 176][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2182.1]
[PID: 228][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2191.1.296.2]
[PID: 240][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2184.1]
[PID: 408][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 436][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2161.1]
[C:\WINNT\system32\CNMLM6e.DLL] [CANON INC., 1.80.2.50]
[C:\WINNT\system32\OLFMNT40.DLL] [Microsoft Corporation, 9.0.98.0105]
[C:\WINNT\System32\spool\PRTPROCS\W32X86\CNMPD6e.DLL] [CANON INC., 1.80.2.50]
[C:\WINNT\System32\spool\PRTPROCS\W32X86\olfpnt40.dll] [Microsoft Corporation, 9.0.98.0105]
[PID: 480][C:\WINNT\System32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 508][d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00]
[PID: 612][C:\WINNT\system32\regsvc.exe] [Microsoft Corporation, 5.00.2155.1]
[PID: 704][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0001]
[PID: 960][C:\WINNT\Explorer.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[C:\WINNT\downlo~1\Kchtaa.dll] [Tencent, 4, 4, 1, 14]
[D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[C:\WINNT\System32\iodbzfex.dll] [, 1, 0, 0, 4]
[C:\WINNT\System32\cuhqndbc.dll] [, 1, 0, 0, 24]
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[D:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL] [N/A, N/A]
[C:\WINNT\System32\ergaon.dll] [N/A, N/A]
[PID: 1064][C:\Program Files\VIA\RAID\raid_tool.exe] [VIA Technologies, 4, 0, 6, 0]
[C:\Program Files\VIA\RAID\drvInterface.dll] [VIA, 4, 0, 4, 0]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[PID: 1128][C:\WINNT\System32\TDHelp32.exe] [N/A, N/A]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[PID: 1140][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3427]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[PID: 1180][C:\WINNT\System32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\ergaon.dll] [N/A, N/A]
[PID: 536][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] [Microsoft Corporation, 2000.080.0194.00]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[C:\WINNT\System32\ergaon.dll] [N/A, N/A]
[PID: 1320][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\downlo~1\Kchtaa.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[C:\Program Files\MySec\secbaraai.dll] [SemeanKitty's Office, 1.00.05]
[D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[C:\Program Files\TENCENT\Adplus\SSAddr.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\xBar\xBarHelper.dll] [N/A, 1.0.0.8]
[C:\WINNT\System32\iodbzfex.dll] [, 1, 0, 0, 4]
[d:\Program Files\Tencent\QQ\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
[C:\WINNT\System32\ssup.dll] [TENCENT, 4, 4, 1, 15]
[C:\Program Files\MySec\secmouseaai.dll] [SemeanKitty's Office, 1.00.04]
[C:\WINNT\System32\cuhqndbc.dll] [, 1, 0, 0, 24]
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[C:\WINNT\System32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINNT\System32\ergaon.dll] [N/A, N/A]
[PID: 1352][C:\WINNT\System32\drivers\spoclsv.exe] [N/A, N/A]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[PID: 7196][C:\WINNT\System32\ergaon.exe] [N/A, N/A]
[C:\WINNT\System32\ergaon.dll] [N/A, N/A]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[PID: 9200][D:\瑞星专杀工具\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINNT\downlo~1\Jwgs.dll] [Tencent, 4, 4, 1, 14]
[C:\WINNT\System32\TDGL32.dll] [N/A, N/A]
[C:\WINNT\System32\ergaon.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[D:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[E:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[F:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
[/CODE]
szlilong - 2007-1-13 14:34:00
下面的方法解决不了
IceSword冰刃-斩断木马黑手的利刃
下载地址1:
中文:http://202.38.64.10/~jfpan/download/IceSword120_cn.zip
MD5 : cfb8514add1fbfb510b0084e837e561c
下载地址2:http://free.ys168.com/?ljs3508反病毒及安全工具区,
文件名:IceSword120_cn.zip 2.1MB
使用IceSword杀毒的一些基本操作
http://forum.ikaka.com/topic.asp?board=28&artid=7168178
展开:[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<cmdbcs><C:\WINNT\cmdbcs.exe> [Microsoft Corporation]
<wabqpt><C:\WINNT\system32\ynxevc.exe> [N/A]
展开[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINNT\system32\userinit.exe,C:\WINNT\system\userinit.exe> [N/A]红色的删掉
打开注册表编辑器,定位到HKEY_LOCAL_MACHINE\ SYSTEM\ CURRENT CONTROLSET\ SERVICES
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINNT\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
<C:\WINNT\system32\rundll32.exe xpdhcp.dll,start><Microsoft Corporation>
1、下载、运行IceSword。
2、用IceSword禁止进程创建。
3、找到并右击IceSword自身的进程名,点击“模块信息”。仔细查看模块中是否有
[C:\WINNT\system32\windhcp.ocx]
[C:\WINNT\system32\xpdhcp.dll]
[C:\WINNT\system32\ynxevc.dll] 。如果有,用IceSword强制卸除之(千万不要省略这一步)。
4、用IceSword结束除下列进程以外的进程(已经被病毒模块插入了):
[PID: 152][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 176][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 172][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6714]
[PID: 224][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.6700]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 236][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.6695]
[PID: 408][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 496][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.6659]
5、用IceSword删除上述加载项(红字内容)。
6、用IceSword删除以下文件。
C:\WINNT\system\userinit.exe
C:\WINNT\TEMP\gg.exe
C:\WINNT\system32\windhcp.ocx
C:\WINNT\system32\ynxevc.dll
C:\WINNT\system32\iexpl0re.exe
C:\WINNT\system32\windhcp.ocx
C:\WINNT\TEMP\LgSym.dll
C:\Progra~1\Eset\rund1132.exe
C:\WINNT\system32\windhcp.ocx
C:\WINNT\system32\xpdhcp.dll
C:\WINNT\system32\lexplore.exe
C:\WINNT\system\userinit.exe
删除D,E,F下的
Autorun.inf sxs.exe
清空。。C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
7、点击IceSword工具栏上的“文件”、“设置”,取消“禁止进程创建”。
8、点击IceSword工具栏上的“文件”、“重启并监视”。此时,系统重启。
禁用远程注册表修改服务。。重新扫日志传上来 给系统administrator 加密。。
© 2000 - 2026 Rising Corp. Ltd.