瑞星卡卡安全论坛
YANGYANGTE - 2007-2-2 17:00:00
进程表里有5个IE进程然后用木马客星,瑞星,卡巴查不出,同时有浏览器被劫持的弹出窗口(用几种常用的流氓软件查杀不到),然后还有WORM.VIKING.BB的余毒.请高手费心指点
Logfile of HijackThis v1.99.1
Scan saved at 16:31:54, on 2007-2-2
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\VM303_STI.EXE
E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX16.984\木马杀客\mmsk.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX18.109\HijackThis.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [kav] "E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4F523D5-2CD6-4F04-AA3F-07E204A6C1E2}: NameServer = 61.153.177.196
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - D:\PROGRA~1\KuGoo3\InExtend\KUGOO3~1.OCX (file missing)
O23 - Service: 卡巴斯基反病毒6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
PS:现在连安全模式都挂了。太可恶了鸟...
长期潜水 - 2007-2-2 17:09:00
估计是ROOTKIT
换用SRENG扫描驱动
孤独更可靠 - 2007-2-2 17:11:00
C:\WINDOWS\VM303_STI.EXE
其他没发现什么不正常的...
我是一条肥鱼 - 2007-2-2 17:42:00
| 引用: |
【孤独更可靠的贴子】C:\WINDOWS\VM303_STI.EXE
其他没发现什么不正常的...
……………… |
大哥C:\WINDOWS\VM303_STI.EXE是摄相头
孤独更可靠 - 2007-2-2 17:47:00
..哈~..
那其他没发现什么不正常的了..
都是写软件的挂勾.没用可以去掉~..
C:\Program Files\Internet Explorer\iexplore.exe
如果你没打开的话,那可能是灰鸽子..先下个专杀..
然后推荐你个软件可以解决问题:
WINDOWS 清理助手
官方下载地址:http://www.arswp.com/download/arswp/arswp.rar
寻找北方的哥儿 - 2007-2-2 17:47:00
没看出什么问题,只看出一些流氓软件,清一下吧
水树雨下 - 2007-2-2 18:05:00
要sreng2日志
YANGYANGTE - 2007-2-2 22:14:00
2007-02-18,21:58:51
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe> [(Verified)Google Inc.]
<win><C:\WINDOWS\Temp\serlass.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<avp6_post_uninstall><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> D:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[cmd]
<C:\Documents and Settings\Queenya\「开始」菜单\程序\启动\cmd.lnk --> C:\WINDOWS\Temp\serlass.exe [N/A]><N>
==================================
服务
[F6EF7AE4 / F6EF7AE4][Stopped/Auto Start]
<C:\WINDOWS\system32\F6EF7AE4.EXE -service><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[kl1 / kl1][Running/Disabled]
<system32\drivers\kl1.sys><N/A>
[klif / klif][Running/Disabled]
<\??\C:\WINDOWS\system32\drivers\klif.sys><N/A>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[vmfilter303 / vmfilter303][Running/Manual Start]
<system32\drivers\vmfilter303.sys><Vimicro Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[AONI PC Cam(Vimicro301 Neptune) / ZSMC303][Running/Manual Start]
<System32\Drivers\usbVM303.sys><Vimicro Corporation>
==================================
浏览器加载项
[快速搜索]
{BF5DC4AE-258C-43d5-9D80-1F7ACD734DD8} <C:\WINDOWS\Temp\sjbbx.exe, N/A>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
==================================
YANGYANGTE - 2007-2-2 22:16:00
正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 620][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 644][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 688][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 856][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1068][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1124][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1292][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1472][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1836][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 336][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[PID: 432][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 692][C:\WINDOWS\VM303_STI.EXE] [Vimicro, 4, 3, 625, 61]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\VM303Prp.Ax] [Vimicro, 3, 6, 411, 13]
[PID: 1748][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3536]
[PID: 1756][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1760][C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe] [Google Inc., 1, 2, 911, 3380]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\res_zh-CN.dll] [Google Inc., 1, 2, 911, 3380]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\swg.dll] [Google Inc., 1, 2, 911, 3380]
[PID: 744][C:\WINDOWS\Temp\serlass.exe] [N/A, N/A]
[C:\DOCUME~1\Queenya\LOCALS~1\Temp\E_4\krnln.fnr] [, 1, 0, 0, 1]
[C:\DOCUME~1\Queenya\LOCALS~1\Temp\E_4\HtmlView.fne] [, 1, 0, 0, 1]
[C:\DOCUME~1\Queenya\LOCALS~1\Temp\E_4\shell.fne] [N/A, N/A]
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] [N/A, N/A]
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [N/A, N/A]
[E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [N/A, N/A]
[PID: 2212][C:\WINDOWS\system32\msiexec.exe] [Microsoft Corporation, 3.1.4000.1823]
[PID: 3544][C:\Documents and Settings\Queenya\桌面\arswp\arswp\ArSwp.exe] [www.arswp.com, 1, 6, 6, 7]
[C:\DOCUME~1\Queenya\桌面\arswp\arswp\ArSwp.dll] [www.arswp.com, 1, 6, 12, 7]
[PID: 2996][C:\Program Files\Real\RealPlayer\realplay.exe] [RealNetworks, Inc., 6.0.12.1506]
[C:\WINDOWS\system32\PNCRT.dll] [Real Networks, Inc, 6.0.0.0]
[C:\Program Files\Common Files\Real\Common\objb3201.dll] [RealNetworks, Inc., 0.1.0.6442]
[C:\Program Files\Real\RealPlayer\rpplugins\rpap3260.dll] [RealNetworks, Inc., 6.0.9.3064]
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.4093]
[C:\Program Files\Real\RealPlayer\lang\cdplay_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\dbcomp_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\embed_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\gemctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\pngui_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\pdgenxfer_cn.dll] [N/A, N/A]
[C:\Program Files\Real\RealPlayer\lang\rjctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjeq_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjres_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjskin_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjviz_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjfade_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjdlg_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjmisc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjprog_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpapp_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpclsvc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpclutil_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[C:\Program Files\Real\RealPlayer\lang\rpdemand_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[C:\Program Files\Real\RealPlayer\lang\rpdsplyr_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpgutil_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpmnpane_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpplylst_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpwebctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tcdinfo_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tclsvc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tdwnmgr_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tmp3_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\twave_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\teasdk_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tearm_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tmdedit_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\mydevices_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[C:\Program Files\Real\RealPlayer\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.3137]
[C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll] [RealNetworks, Inc., 0.1.0.3858]
[C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] [RealNetworks, Inc., 6.0.8.2575]
[C:\Program Files\Common Files\Real\Plugins\smplfsys.dll] [RealNetworks, Inc., 10.0.0.1989]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols1.dll] [RealNetworks, Inc., 6.0.1.2259]
[C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll] [RealNetworks, Inc., 1.0.0.4020]
[C:\Program Files\Real\RealPlayer\rpplugins\rpmn3260.dll] [RealNetworks, Inc., 6.0.9.2960]
[C:\Program Files\Real\RealPlayer\rpplugins\rpwe3260.dll] [RealNetworks, Inc., 6.0.1.2303]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols2.dll] [RealNetworks, 6.0.1.2259]
[C:\Program Files\Real\RealPlayer\rpplugins\rpms3260.dll] [RealNetworks, Inc., 6.0.1.2297]
[C:\Program Files\Real\RealPlayer\rpplugins\MPACore.dll] [RealNetworks, Inc., 1.0.3.2316]
[C:\Program Files\Real\RealPlayer\rpplugins\rppl3260.dll] [RealNetworks, Inc., 6.0.1.2298]
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.2737]
[C:\Program Files\Real\RealPlayer\rpplugins\myde3260.dll] [RealNetworks, Inc., 6.0.10.2524]
[C:\Program Files\Common Files\Real\Common\pnen3260.dll] [RealNetworks, Inc., 10.0.0.1250]
[C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] [RealNetworks, Inc., 10.1.0.1147]
[C:\Program Files\Common Files\Real\Plugins\vidsite.dll] [RealNetworks, Inc., 10.0.0.1220]
[C:\Program Files\Common Files\Real\Plugins\clntxres.dll] [RealNetworks, Inc., 10.0.0.4106]
[C:\Program Files\Common Files\Real\Plugins\smlfformat.dll] [RealNetworks, Inc., 10.0.0.2081]
[C:\Program Files\Common Files\Real\Plugins\ramfformat.dll] [RealNetworks, Inc., 10.0.0.2446]
[C:\Program Files\Real\RealPlayer\plugins\wmaimprtpln.dll] [RealNetworks, Inc., 6.0.9.1000]
[C:\Program Files\Real\RealPlayer\rjwmapln.dll] [RealNetworks, Inc., 6.0.8.1795]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\Common Files\Real\Plugins\smlrender.dll] [RealNetworks, Inc., 10.0.0.1697]
[C:\Program Files\Common Files\Real\Plugins\authmgr.dll] [RealNetworks, Inc., 10.0.0.1654]
[C:\Program Files\Common Files\Real\Common\rjbviz.dll] [RealNetworks, Inc., 1.0.2.3917]
[C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv] [RealNetworks, Inc., 1.0.0.2]
[C:\Program Files\Common Files\Real\Visualizations\Fire.rpv] [RealNetworks, Inc., 1.0.0.1]
[C:\Program Files\Common Files\Real\Visualizations\FreqBands.rpv] [RealNetworks, Inc., 1.0.0.2]
[C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll] [RealNetworks, Inc., 0.1.0.3536]
[C:\Program Files\Real\RealPlayer\rpplugprot.dll] [RealNetworks, Inc., 6.0.10.2264]
[C:\Program Files\Common Files\Real\Common\twebbrowse.dll] [RealNetworks, Inc., 1.0.2.1619]
[C:\Program Files\Real\RealPlayer\rpplugins\mpazip.dll] [RealNetworks, Inc., 1.0.4.2315]
[C:\Program Files\Real\RealPlayer\dunzip32.dll] [Inner Media, Inc., 5.00.03]
[C:\Program Files\Common Files\Real\RCAPlugins\gemx3201.dll] [RealNetworks, Inc., 0.1.0.5895]
[C:\Program Files\Real\RealPlayer\rpplugins\rpwm3260.dll] [RealNetworks, Inc., 6.0.9.1000]
[C:\Program Files\Real\RealPlayer\rpplugins\rpcomproxy.dll] [RealNetworks, Inc., 6.0.12.1015]
[C:\Program Files\Real\RealPlayer\rpplugins\rjbe3260.dll] [RealNetworks, Inc., 6.0.4.2299]
[C:\WINDOWS\system32\ffdshow.ax] [N/A, 1.0.2.2028]
[C:\Program Files\Real\RealPlayer\rdsf3260.dll] [RealNetworks, Inc., 6.0.12.1251]
[C:\Program Files\Common Files\Real\RCAPlugins\sonr3210.dll] [RealNetworks, Inc., 1.0.0.2356]
[PID: 3292][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_003.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[PID: 1560][d:\Program Files\WinRAR\WinRAR.exe] [N/A, N/A]
[PID: 2004][C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX00.656\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
YANGYANGTE - 2007-2-2 22:16:00
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
YANGYANGTE - 2007-2-2 22:19:00
| 引用: |
【寻找北方的哥儿的贴子】没看出什么问题,只看出一些流氓软件,清一下吧 ……………… |
这些流氓软件说下卡卡 流氓清除专家 超级兔子 优化大师WOPTI 木马客星 都清除不了
卡卡甚至发现不了
YANGYANGTE - 2007-2-2 22:25:00
| 引用: |
【孤独更可靠的贴子】..哈~.. 那其他没发现什么不正常的了.. 都是写软件的挂勾.没用可以去掉~..
C:\Program Files\Internet Explorer\iexplore.exe
如果你没打开的话,那可能是灰鸽子..先下个专杀..
然后推荐你个软件可以解决问题: WINDOWS 清理助手 官方下载地址:http://www.arswp.com/download/arswp/arswp.rar
……………… |
这个
C:\Program Files\Internet Explorer\iexplore.exe
的进程和服务符合灰鸽子的情况 木马客星提示了可是杀不掉 估计是变种的变种 被用来开后门传流氓软件的 . 瑞星和卡巴全灭.. WINDOWS 清理助手 不错干掉几个流氓
中病毒就豁了 - 2007-2-2 22:27:00
没什么 不正常的啊 没病毒啊 我也是新手 呵呵
YANGYANGTE - 2007-2-2 22:29:00
| 引用: |
【中病毒就豁了的贴子】没什么 不正常的啊 没病毒啊 我也是新手 呵呵 ……………… |
OTL
YANGYANGTE - 2007-2-2 22:37:00
额..现在重启了下 时间被改到1987年10月 2日 然后卡巴提示时间错误..把时间改回..卡巴挂了。...额........
真是命苦啊..先中VIKING再中流氓再中IE劫持 再中灰鸽子..两天内的事情.
WOW都米得玩 55555
水树雨下 - 2007-2-3 11:01:00
运行sreng2启动项目,注册表删除
[(Verified)Google Inc.]
<win><C:\WINDOWS\Temp\serlass.exe> [N/A]
启动项目,服务,win32服务应用程序,勾选隐藏微软服务后删除
[F6EF7AE4 / F6EF7AE4][Stopped/Auto Start]
<C:\WINDOWS\system32\F6EF7AE4.EXE -service><N/A>
系统修复,浏览器加载项删除
[快速搜索]
{BF5DC4AE-258C-43d5-9D80-1F7ACD734DD8} <C:\WINDOWS\Temp\sjbbx.exe, N/A>
安全模式下打开我的电脑,工具,文件夹选项,查看,显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉删除
:\WINDOWS\system32\F6EF7AE4.EXE
这个文件夹所有文件
C:\WINDOWS\Temp
C:\DOCUME~1\Queenya\LOCALS~1\Temp
YANGYANGTE - 2007-2-3 11:15:00
| 引用: |
【水树雨下的贴子】运行sreng2启动项目,注册表删除 [(Verified)Google Inc.] <win><C:\WINDOWS\Temp\serlass.exe> [N/A] 启动项目,服务,win32服务应用程序,勾选隐藏微软服务后删除 [F6EF7AE4 / F6EF7AE4][Stopped/Auto Start] <C:\WINDOWS\system32\F6EF7AE4.EXE -service><N/A> 系统修复,浏览器加载项删除 [快速搜索] {BF5DC4AE-258C-43d5-9D80-1F7ACD734DD8} <C:\WINDOWS\Temp\sjbbx.exe, N/A> 安全模式下打开我的电脑,工具,文件夹选项,查看,显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉删除 :\WINDOWS\system32\F6EF7AE4.EXE 这个文件夹所有文件 C:\WINDOWS\Temp C:\DOCUME~1\Queenya\LOCALS~1\Temp ……………… |
额..安全模式被挂掉了..
水树雨下 - 2007-2-3 11:17:00
那就把安全模式改成重启,删不掉用冰刃
YANGYANGTE - 2007-2-3 11:23:00
| 引用: |
【水树雨下的贴子】那就把安全模式改成重启,删不掉用冰刃 ……………… |
改成重启?不明白 .
能修复么?
貌似现在的IE弹出窗口正常了但是进程里还素有3个IEXPLORE.EXE
等偶再发个SRENG2给你瞧瞧~~
酷酷々小孩〃 - 2007-2-3 11:24:00
楼主可怜帮你顶
YANGYANGTE - 2007-2-3 11:25:00
2007-02-19,11:18:12
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe> [(Verified)Google Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<avp6_post_uninstall><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> D:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[cmd]
<C:\Documents and Settings\Queenya\「开始」菜单\程序\启动\cmd.lnk --> C:\WINDOWS\Temp\serlass.exe [N/A]><N>
==================================
服务
[F6EF7AE4 / F6EF7AE4][Stopped/Auto Start]
<C:\WINDOWS\system32\F6EF7AE4.EXE -service><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[kl1 / kl1][Running/Disabled]
<system32\drivers\kl1.sys><N/A>
[klif / klif][Running/]
<2 - 系统找不到指定的文件。
><N/A>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[vmfilter303 / vmfilter303][Running/Manual Start]
<system32\drivers\vmfilter303.sys><Vimicro Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[AONI PC Cam(Vimicro301 Neptune) / ZSMC303][Running/Manual Start]
<System32\Drivers\usbVM303.sys><Vimicro Corporation>
==================================
浏览器加载项
[快速搜索]
{BF5DC4AE-258C-43d5-9D80-1F7ACD734DD8} <C:\WINDOWS\Temp\sjbbx.exe, N/A>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
==================================
水树雨下 - 2007-2-3 11:26:00
重启后打开我的电脑,工具,文件夹选项,查看,显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉删除
:\WINDOWS\system32\F6EF7AE4.EXE
这个文件夹所有文件
C:\WINDOWS\Temp
C:\DOCUME~1\Queenya\LOCALS~1\Temp
YANGYANGTE - 2007-2-3 11:27:00
正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 620][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 644][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 688][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 856][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1068][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1124][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1292][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1472][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1836][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 336][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[PID: 432][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 692][C:\WINDOWS\VM303_STI.EXE] [Vimicro, 4, 3, 625, 61]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\VM303Prp.Ax] [Vimicro, 3, 6, 411, 13]
[PID: 1748][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3536]
[PID: 1756][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1760][C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe] [Google Inc., 1, 2, 911, 3380]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\res_zh-CN.dll] [Google Inc., 1, 2, 911, 3380]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\swg.dll] [Google Inc., 1, 2, 911, 3380]
[PID: 3632][C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX01.578\Iparmo\Iparmor\iparmor.exe] [luosoft.com, 5.5.0.0]
[C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX01.578\Iparmo\Iparmor\getportlistxp.dll] [, 1, 0, 0, 1]
[C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX01.578\Iparmo\Iparmor\hookhookdll.dll] [N/A, N/A]
[PID: 3964][C:\Program Files\BitComet\BitComet.exe] [www.BitComet.com, 0.82]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 2924][c:\program files\internet explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3656][C:\Program Files\Real\RealPlayer\realplay.exe] [RealNetworks, Inc., 6.0.12.1506]
[C:\WINDOWS\system32\PNCRT.dll] [Real Networks, Inc, 6.0.0.0]
[C:\Program Files\Common Files\Real\Common\objb3201.dll] [RealNetworks, Inc., 0.1.0.6442]
[C:\Program Files\Real\RealPlayer\rpplugins\rpap3260.dll] [RealNetworks, Inc., 6.0.9.3064]
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.4093]
[C:\Program Files\Real\RealPlayer\lang\cdplay_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\dbcomp_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\embed_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\gemctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\pngui_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\pdgenxfer_cn.dll] [N/A, N/A]
[C:\Program Files\Real\RealPlayer\lang\rjctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjeq_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjres_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjskin_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjviz_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjfade_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjdlg_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjmisc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rjprog_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpapp_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpclsvc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpclutil_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[C:\Program Files\Real\RealPlayer\lang\rpdemand_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[C:\Program Files\Real\RealPlayer\lang\rpdsplyr_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpgutil_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpmnpane_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpplylst_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\rpwebctl_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tcdinfo_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tclsvc_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tdwnmgr_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tmp3_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\twave_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\teasdk_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tearm_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\tmdedit_cn.dll] [RealNetworks, Inc., 6.0.12.298]
[C:\Program Files\Real\RealPlayer\lang\mydevices_cn.dll] [RealNetworks, Inc., 6.0.12.299]
[C:\Program Files\Real\RealPlayer\rpplugins\rpcl3260.dll] [RealNetworks, Inc., 6.0.9.3137]
[C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll] [RealNetworks, Inc., 0.1.0.3858]
[C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] [RealNetworks, Inc., 6.0.8.2575]
[C:\Program Files\Common Files\Real\Plugins\smplfsys.dll] [RealNetworks, Inc., 10.0.0.1989]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols1.dll] [RealNetworks, Inc., 6.0.1.2259]
[C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll] [RealNetworks, Inc., 1.0.0.4020]
[C:\Program Files\Real\RealPlayer\rpplugins\rpmn3260.dll] [RealNetworks, Inc., 6.0.9.2960]
[C:\Program Files\Real\RealPlayer\rpplugins\rpwe3260.dll] [RealNetworks, Inc., 6.0.1.2303]
[C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols2.dll] [RealNetworks, 6.0.1.2259]
[C:\Program Files\Real\RealPlayer\rpplugins\rpms3260.dll] [RealNetworks, Inc., 6.0.1.2297]
[C:\Program Files\Real\RealPlayer\rpplugins\MPACore.dll] [RealNetworks, Inc., 1.0.3.2316]
[C:\Program Files\Real\RealPlayer\rpplugins\rppl3260.dll] [RealNetworks, Inc., 6.0.1.2298]
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] [RealNetworks, Inc., 6.7.0.2737]
[C:\Program Files\Real\RealPlayer\rpplugins\myde3260.dll] [RealNetworks, Inc., 6.0.10.2524]
[C:\Program Files\Real\RealPlayer\rjwmapln.dll] [RealNetworks, Inc., 6.0.8.1795]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\Common Files\Real\Common\pnen3260.dll] [RealNetworks, Inc., 10.0.0.1250]
[C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] [RealNetworks, Inc., 10.1.0.1147]
[C:\Program Files\Common Files\Real\Plugins\vidsite.dll] [RealNetworks, Inc., 10.0.0.1220]
[C:\Program Files\Common Files\Real\Plugins\clntxres.dll] [RealNetworks, Inc., 10.0.0.4106]
[C:\Program Files\Common Files\Real\Plugins\smlfformat.dll] [RealNetworks, Inc., 10.0.0.2081]
[C:\Program Files\Real\RealPlayer\rpplugins\rjbe3260.dll] [RealNetworks, Inc., 6.0.4.2299]
[C:\Program Files\Common Files\Real\Plugins\ramfformat.dll] [RealNetworks, Inc., 10.0.0.2446]
[C:\Program Files\Common Files\Real\Plugins\smlrender.dll] [RealNetworks, Inc., 10.0.0.1697]
[C:\Program Files\Common Files\Real\Plugins\authmgr.dll] [RealNetworks, Inc., 10.0.0.1654]
[C:\Program Files\Common Files\Real\Common\rjbviz.dll] [RealNetworks, Inc., 1.0.2.3917]
[C:\Program Files\Common Files\Real\Codecs\hxltcolor.dll] [RealNetworks, Inc., 10.0.0.1077]
[C:\Program Files\Real\RealPlayer\rpplugprot.dll] [RealNetworks, Inc., 6.0.10.2264]
[C:\Program Files\Common Files\Real\Common\twebbrowse.dll] [RealNetworks, Inc., 1.0.2.1619]
[C:\Program Files\Common Files\Real\RCAPlugins\gemx3201.dll] [RealNetworks, Inc., 0.1.0.5895]
[C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv] [RealNetworks, Inc., 1.0.0.2]
[C:\Program Files\Real\RealPlayer\plugins\rjrmjpln.dll] [RealNetworks, Inc., 1.0.3.2270]
[C:\Program Files\Common Files\Real\Plugins\rmfformat.dll] [RealNetworks, Inc., 10.0.0.1442]
[C:\Program Files\Common Files\Real\Plugins\rarender.dll] [RealNetworks, Inc., 10.0.0.1227]
[C:\Program Files\Common Files\Real\Plugins\rvrender.dll] [RealNetworks, Inc., 10.0.0.1611]
[C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll] [RealNetworks, Inc., 0.1.0.3536]
[C:\Program Files\Common Files\Real\RCAPlugins\gema3201.dll] [RealNetworks, Inc., 0.1.0.3841]
[C:\Program Files\Real\RealPlayer\rpplugins\rjbc3260.dll] [RealNetworks, Inc., 6.0.1.2304]
[C:\Program Files\Real\RealPlayer\tnetdtct.dll] [RealNetworks, Inc., 1.0.3.2264]
[C:\Program Files\Common Files\Real\Codecs\cook.dll] [RealNetworks, Inc., 10.0.0.2313]
[C:\Program Files\Common Files\Real\Codecs\RV40.DLL] [RealNetworks, Inc., 10.0.0.1707]
[C:\Program Files\Common Files\Real\Codecs\drvc.dll] [RealNetworks, Inc., 10.0.0.1707]
[PID: 3576][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3500][d:\Program Files\WinRAR\WinRAR.exe] [N/A, N/A]
[PID: 2228][C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX00.375\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
YANGYANGTE - 2007-2-3 11:31:00
:\WINDOWS\system32\F6EF7AE4.EXE 米有了...不见了。 ..我也米删除....
C:\WINDOWS\Temp
C:\DOCUME~1\Queenya\LOCALS~1\Temp
额..重启还素删不掉 ~
安全模式怀疑被破坏 ..卡巴已经被病毒挂掉瑞星已经被我删掉 现在除了IE主页 继续被劫http://www.china3q.com/index.htm?hh持外 有3个IE进程
YANGYANGTE - 2007-2-3 11:33:00
PS:机器里貌似还有WORM.VIKING.BB的残余势力
由于空间限制 重装系统是下下策...OTL.............
1
© 2000 - 2026 Rising Corp. Ltd.