瑞星卡卡安全论坛
hurryhx2 - 2007-2-4 14:44:00
我上网从来都不开病毒防火墙
不小心打开了一个小网站下载下来的工具
于是中了一大片流氓软件
经过一个早上的奋战
病毒已经消灭了一大半
但是仍然有一个杀不掉
360、兔子、金山都监测不出来
文件名也很怪异 随机生成的几个字母 见图
症状:一开机explorer.exe CPU达到100
桌面不会显示
把文件删除 启动项删除 重起以后又会生成
ICESWORD也用不了 提示初始化错误 驱动好像也被破坏 想看看线程也看不了
附件:
410577200724143511.jpg
hurryhx2 - 2007-2-4 14:53:00
hope…… - 2007-2-4 14:56:00
用《瑞星卡卡上网安全助手》试试看吧。
寻找北方的哥儿 - 2007-2-4 14:59:00
服务和驱动程序有没有去改?
hurryhx2 - 2007-2-4 14:59:00
更正:病毒一旦删除立即再生
且无法更改文件名(任何提示也没有 重命名更改名字以后无效)
hurryhx2 - 2007-2-4 15:00:00
服务已经把不正常的删了好多
但是还是没用
我这里安全模式 还是不能动病毒文件(删除立即再生 无法改名 无提示)
寻找北方的哥儿 - 2007-2-4 15:04:00
还能扫个日志放上来看看吗?
hurryhx2 - 2007-2-4 15:08:00
日志太多了 论坛要求12000字以内……
我这里安全模式速度极慢
不过也能分段发上来 马上就发
费尔删除工具提示文件正在使用…………
帮帮我ya - 2007-2-4 15:10:00
一次贴不完 分次贴
hurryhx2 - 2007-2-4 15:10:00
[CODE]
2007-02-03,06:38:51
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<TweakWindow><D:\Program Files\TweakWindow\TweakWin.exe> [AbsoluteWay]
<jiajiasr><D:\Program Files\jj4\jiajiasr.exe> [加加工作组]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [Microsoft Corporation]
<KavPFW><"D:\KAV2007\KPFW32.EXE"> [N/A]
<534mvbt40><C:\WINDOWS\systom.exe> [N/A]
<BossKey><; > [N/A]
<eMuleAutoStart><; D:\Program Files\eMule\eMule.exe -AutoStart> [http://www.emule.org.cn]
<kubao><; C:\Program Files\kubao\kubao.exe -autorun> [N/A]
<LetsCool><; C:\Program Files\LetsCool\LetsCool.exe> [N/A]
<pbmini><; C:\Program Files\pcast\PodcastbarMini\PodcastBarMiniStater.exe> [N/A]
<VoipBuster><; "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized> [N/A]
<词霸Online自启动><; d:\Program Files\Kingsoft\iciba\Iciba.exe> [Kingsoft]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<MemEmpty><D:\memempty\MemEmpty.exe /h> [www.jpexe.com]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Corporation]
<MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A]
<Apoint><C:\Program Files\Apoint\Apoint.exe> [(Verified)Alps Electric Co., Ltd.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)RealNetworks, Inc.]
<TCmem><D:\TCmem\TCmem.exe> [天才梦工作室 www.tcmeng.com]
<KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k> [N/A]
hurryhx2 - 2007-2-4 15:10:00
<KavStart><"D:\KAV2007\KAVStart.exe" -startup> [N/A]
<kav><; "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
<MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [(Verified)Microsoft Corporation]
<Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll> [N/A]
<wsvbs><C:\WINDOWS\wsvbs.exe> [N/A]
<CONFIG><C:\DOCUME~1\xhst\LOCALS~1\Temp\8.exe> [N/A]
<ats><; C:\WINDOWS\system32\asd\loadqm.exe noshow> [N/A]
<CdnCtr><; C:\Program Files\CNNIC\Cdn\cdnup.exe> [N/A]
<CnsMHlp.exe><; C:\WINDOWS\Downloaded Program files\CnsMHlp.exe> [N/A]
<DAEMON Tools-2052><; "D:\Program Files\D-Tools\daemon.exe" -lang 2052> [DAEMON'S HOME]
<Dell QuickSet><; C:\Program Files\Dell\QuickSet\quickset.exe> [N/A]
<dla><; C:\WINDOWS\system32\dla\tfswctrl.exe> [N/A]
<DVDLauncher><; "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"> [CyberLink Corp.]
<helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> [N/A]
<ISUSPM Startup><; C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup> [InstallShield Software Corporation]
<ISUSScheduler><; "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start> [InstallShield Software Corporation]
<MoveSearch><; C:\Program Files\HuaCi\huaci\zsearch.exe> [N/A]
<MSService_v1.0><; C:\WINDOWS\system\java.exe> [N/A]
<NeroCheck><; ; rem C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<NetpasAcc><; D:\Program Files\NETPAS\NETPAS ACC\Netpas_Acc.exe> [N/A]
<New.net Startup><; rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s> [N/A]
<PigUpdate><; C:\DOCUME~1\xhst\LOCALS~1\Temp\dlPig.exe> [N/A]
<RavMon><; D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM> [N/A]
<RavTimer><; C:\Program Files\rising\rav\RavTimer.exe> [N/A]
<res><; C:\WINDOWS\system32\res.exe> [N/A]
<RfwMain><; "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [N/A]
<RichMedia><; C:\WINDOWS\system32\Rundll32.exe "C:\PROGRA~1\hbclient\HBHelper.dll",WaitWindows> [N/A]
<sdafdsafds><; D;]XJOEPXT]ufnq]te264/fyf> [N/A]
<SKYNET Personal FireWall><; C:\PROGRA~1\SkyNet\FireWall\pfw.exe> [N/A]
<SmpartProxy><; D:\proxysetup\EyouProxy.exe> []
<spoolsv><; > [N/A]
<StormCodec_Helper><; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<SunJavaUpdateSched><; C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe> [N/A]
<SysExplr><; D:\Program Files\Herosoft\HeroV8\SYSEXPLR.EXE> [N/A]
<Thunder><; "D:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s> [N/A]
<Update><; C:\Program Files\Common Files\UPDAT\Update.exe> [N/A]
<UpdateManager><; "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r> [N/A]
<Updater><; C:\PROGRA~1\HenBang\Update\Update.exe> [N/A]
<UVS10 Preload><; d:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe> [Ulead Systems, Inc.]
<VikaClient><; "C:\Program Files\VIKA\vkclient.exe"> [N/A]
<WebThunder><; d:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [深圳市迅雷网络技术有限公司]
<Winrun><; C:\WINDOWS\bqq.exe> [N/A]
<yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [N/A]
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [N/A]
<YOKAssiant><; Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant> [N/A]
<zcom><; C:\Program Files\zcom\zPlatform.exe MIN> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<360Safe><Rundll32.exe D:\PROGRA~1\360safe\AntiAdwa.dll,KillAdware> [360Safe.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Corporation]
hurryhx2 - 2007-2-4 15:11:00
<{5EED7056-B89D-4DE8-A060-D285EA746795}><C:\WINDOWS\system32\mslaow.dll> [N/A]
<{2D49692C-A5FD-4E29-A3CD-37E9B182FCC6}><C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys> [N/A]
<{4ED6E0B5-F47A-4609-A940-11CF60FDC3C3}><C:\WINDOWS\system32\mctet.dll> []
<{DD7D4640-4464-48C0-82FD-21338366D2D2}><C:\Program Files\Internet Explorer\InfoMs.tdm> [N/A]
<{F47ECABB-ABDB-4e34-8FE8-28DA859BF1ED}><c:\program files\internet explorer\plugins\fxprzszp.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Corporation]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Corporation]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Corporation]
<UPnPMonitor><C:\WINDOWS\system32\upnpui.dll> [(Verified)Microsoft Corporation]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<SysChunk><C:\WINDOWS\system32\syschunk.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg]
<WinlogonNotify: cryptimg><cryptimg.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\BandRes.dll> []
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\system32\logon.scr> [(Verified)Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
[779DF70 / 779DF70][Stopped/Auto Start]
<C:\WINDOWS\system32\779DF70.EXE -service><Microsoft Corporation>
[AB910C28 / AB910C28][Stopped/Auto Start]
<C:\WINDOWS\system32\AB910C28.EXE -service><Microsoft Corporation>
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINDOWS\system32\ati2sgag.exe><>
[卡巴斯基反病毒6.0 / AVP][Stopped/Auto Start]
<"D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[Broadcom ASF IP monitoring service v6.0.4 / BAsfIpM][Stopped/Disabled]
<C:\WINDOWS\system32\basfipm.exe><N/A>
[Intranet Messenger / DATEING][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>
[EvtEng / EvtEng][Stopped/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[File Replication / File Replication][Stopped/Auto Start]
<C:\WINDOWS\system32\ntfis.exe><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Imsvc / Imsvc][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\Webmail.dll><>
[Kingsoft Personal Firewall Service / KPfwSvc][Stopped/Auto Start]
<"D:\KAV2007\KPfwSvc.EXE"><N/A>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Stopped/Auto Start]
<D:\KAV2007\KWatch.EXE><N/A>
[Volume Optimization / License][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\rxdkl.dll><Microsoft Corporation>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[NICCONFIGSVC / NICCONFIGSVC][Stopped/Auto Start]
<C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe><Dell Inc.>
[RegSrvc / RegSrvc][Stopped/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Spectrum24 Event Monitor / S24EventMonitor][Stopped/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation>
[Sample NT Service / SampleService][Stopped/Disabled]
<C:\WINDOWS\NTService.exe><N/A>
[Ulead Burning Helper / UleadBurningHelper][Stopped/Auto Start]
<C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe><Ulead Systems, Inc.>
[Windows XP Vista / Windows XP Vista ][Stopped/Auto Start]
<C:\WINDOWS\Win.ini><N/A>
[Windows Management Controllor / WinMgct][Stopped/Auto Start]
hurryhx2 - 2007-2-4 15:11:00
<C:\WINDOWS\system32\WinMgCt.exe -k netsvcs><N/A>
[WLANKEEPER / WLANKEEPER][Stopped/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe><Intel? Corporation>
[Vsn xknj Service / xknj][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\COMMON~1\dqtp\kxxw.dll,Service><Microsoft Corporation>
[Remote Access Connection Management / Remote Access Connection Management][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ncxml.dll><>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
==================================
驱动程序
[abp480n5 / abp480n5][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[acpidisk / acpidisk][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[adpu64 / adpu64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\adpu64.sys><N/A>
[AEGIS Protocol (IEEE 802.1x) v3.1.0.1 / AegisP][Stopped/Auto Start]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Aha154x / Aha154x][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[Alps Touch Pad Filter Driver for Windows 2000/XP / ApfiltrService][Running/Manual Start]
<system32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[APPDRV / APPDRV][Stopped/System Start]
<\SystemRoot\SYSTEM32\DRIVERS\APPDRV.SYS><Dell Inc>
[asc / asc][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ast / ast][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ast.sys><N/A>
[ati2mtag / ati2mtag][Stopped/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom NetXtreme 57xx Gigabit Controller / b57w2k][Running/Manual Start]
<system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[BM Win32 Network Adapter / bmnadapter][Stopped/Manual Start]
<system32\DRIVERS\bmnet.sys><The OpenVPN Project>
[cd20xrnt / cd20xrnt][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[CmdIde / CmdIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[d347bus / d347bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[dac2w2k / dac2w2k][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[DISK_DRIVE32 / DISK_DRIVE32][Stopped/Manual Start]
<\??\D:\mxdwg\xg042\disk_1024.sys><N/A>
[dpti2o / dpti2o][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[GTIPCI21 / GTIPCI21][Stopped/Manual Start]
<system32\DRIVERS\gtipci21.sys><Texas Instruments>
[gwiopm / gwiopm][Stopped/Manual Start]
<\??\C:\Program Files\Wom\gwiopm.sys><N/A>
[HSFHWICH / HSFHWICH][Stopped/Manual Start]
[/CODE]
hurryhx2 - 2007-2-4 15:11:00
<system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP][Stopped/Manual Start]
<system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ini910u / ini910u][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[Intel Wireless Connection Agent Miniport for Win XP / IWCA][Running/Manual Start]
<system32\DRIVERS\iwca.sys><Intel Corporation>
[jejjdbbf / jejjdbbf][Stopped/Boot Start]
<\SystemRoot\system32\drivers\jejjdbbf.sys><中国互联网络信息中心(CNNIC)>
[kdngrh / kdngrh][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kdngrh.sys><N/A>
[kl1 / kl1][Stopped/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[KNetWch / KNetWch][Stopped/System Start]
<\??\D:\KAV2007\KNetWch.SYS><N/A>
[KWatch3 / KWatch3][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[mdmxsdk / mdmxsdk][Stopped/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[mraid35x / mraid35x][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[msusbbux / msusbbux][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msusbbux.sys><Microsoft Corporation>
[ncio / ncio][Stopped/Auto Start]
<system32\DRIVERS\ncio.sys><N/A>
[Netpas Win32 Virtual Network Adapter / netpasadapter1][Stopped/Manual Start]
<system32\DRIVERS\netpas.sys><Netpas>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><NetGroup - Politecnico di Torino>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\Program Files\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[OMCI WDM Device Driver / omci][Running/System Start]
<system32\DRIVERS\omci.sys><Dell Inc>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[PSSdk23 / PSSdk23][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\PsSdk23.drv><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ql1080 / ql1080][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[R0A / R0A][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\a 3383.sys><N/A>
[WLAN Transport / s24trans][Stopped/Auto Start]
<system32\DRIVERS\s24trans.sys><Intel Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Sparrow / Sparrow][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[SigmaTel C-Major Audio / STAC97][Stopped/Manual Start]
<system32\drivers\STAC97.sys><SigmaTel, Inc.>
[symc810 / symc810][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[sym_hi / sym_hi][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[TosIde / TosIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[tvgame1 / tvgame1][Stopped/Manual Start]
<\??\c:\windows\system32\tvgame.sys><N/A>
[TVICHW32 / TVICHW32][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS><EnTech Taiwan>
[ultra / ultra][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde][Stopped/Disabled]
turkey2k6 - 2007-2-4 15:12:00
IS改名能不能用?或者用近程管理器暂停流氓进程,然后再将文件删除或改名,清理注册表,最后重启电脑再做善后?
hurryhx2 - 2007-2-4 15:15:00
进程里没有流氓进程
它是插入到rundll32.exe里
安全模式下用费尔强制删除工具删除提示文件正在使用…………(进程里没有rundll32.exe)
hurryhx2 - 2007-2-4 15:16:00
<system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP][Stopped/Manual Start]
<system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ini910u / ini910u][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[Intel Wireless Connection Agent Miniport for Win XP / IWCA][Running/Manual Start]
<system32\DRIVERS\iwca.sys><Intel Corporation>
[jejjdbbf / jejjdbbf][Stopped/Boot Start]
<\SystemRoot\system32\drivers\jejjdbbf.sys><中国互联网络信息中心(CNNIC)>
[kdngrh / kdngrh][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kdngrh.sys><N/A>
[kl1 / kl1][Stopped/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[KNetWch / KNetWch][Stopped/System Start]
<\??\D:\KAV2007\KNetWch.SYS><N/A>
[KWatch3 / KWatch3][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[mdmxsdk / mdmxsdk][Stopped/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[mraid35x / mraid35x][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[msusbbux / msusbbux][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msusbbux.sys><Microsoft Corporation>
[ncio / ncio][Stopped/Auto Start]
<system32\DRIVERS\ncio.sys><N/A>
[Netpas Win32 Virtual Network Adapter / netpasadapter1][Stopped/Manual Start]
<system32\DRIVERS\netpas.sys><Netpas>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><NetGroup - Politecnico di Torino>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\Program Files\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[OMCI WDM Device Driver / omci][Running/System Start]
<system32\DRIVERS\omci.sys><Dell Inc>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[PSSdk23 / PSSdk23][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\PsSdk23.drv><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ql1080 / ql1080][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[R0A / R0A][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\a 3383.sys><N/A>
[WLAN Transport / s24trans][Stopped/Auto Start]
<system32\DRIVERS\s24trans.sys><Intel Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Sparrow / Sparrow][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[SigmaTel C-Major Audio / STAC97][Stopped/Manual Start]
<system32\drivers\STAC97.sys><SigmaTel, Inc.>
[symc810 / symc810][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[sym_hi / sym_hi][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[TosIde / TosIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[tvgame1 / tvgame1][Stopped/Manual Start]
<\??\c:\windows\system32\tvgame.sys><N/A>
[TVICHW32 / TVICHW32][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS><EnTech Taiwan>
[ultra / ultra][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[用于 Windows XP 的英特尔(R) PRO/无线 2200BG 网络连接驱动程序 / w29n51][Stopped/Manual Start]
<system32\DRIVERS\w29n51.sys><Intel? Corporation>
[winachsf / winachsf][Stopped/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[WmNdisDrv / WmNdisDrv][Stopped/Manual Start]
<System32\Drivers\WmNdisDrv.sys><N/A>
[wspipe / wspipe][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\wspipe.sys><N/A>
[XScanPF / XScanPF][Stopped/Manual Start]
<\??\D:\hack\X-Scan-v3.3\dat\xpf.sys><N/A>
[NTPort Library Driver / zntport][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\zntport.sys><N/A>
[voodoo / voodoo][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\voodoo.sys><N/A>
==================================
浏览器加载项
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_015.dll, Thunder Networking Technologies,LTD>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\Program Files\DeskAdTop\deskipn.dll, >
[]
{3630cc51-c5d1-492b-8b0d-4e03f37a8dbf} <C:\WINDOWS\system32\492bcfsb.dll, N/A>
[MallObj Class]
{3B30B48F-617D-4F73-A20F-D3D54357F103} <C:\WINDOWS\system32\mallgoo2.dll, 上海奥德易海科技>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[CBrowseStakeout Class]
{55302805-482E-470E-8A57-6795A1487F90} <D:\KAV2007\KAVAFish.DLL, N/A>
[XBTP07757 Class]
{5F915F24-69C2-4ef0-BF74-8A69E4D28E0B} <C:\PROGRA~1\搜阉索骼栏竆\eqiso.dll, N/A>
[BandIE Class]
{77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[XTTBPos00 Class]
{BBBE1C1A-89F7-4AF6-ABD1-1A1DE1C6962A} <C:\PROGRA~1\SOFATO~1\sofa.dll, IE Toolbar>
[f0f]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\4fd4ntos.dll, N/A>
[xhkg]
{E2B4F22C-A9D6-47E0-8D66-9397FC844EC1} <C:\PROGRA~1\COMMON~1\dqtp\huxt.dll, >
hurryhx2 - 2007-2-4 15:16:00
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <D:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <D:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[豪杰超级解霸V8]
{367E0A21-8601-4986-9C9A-153BF5ACA118} <D:\Program Files\Herosoft\HeroV8\STHSDVD.EXE, N/A>
[kele8]
{84920E5F-3788-49cd-A274-E365578DF174} <http://www.kele8.com/, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[sofa]
{B7D3E479-CC68-42B5-A338-B5A0E057163B} <C:\Program Files\SofaToolbar\sofa.dll, IE Toolbar>
[中国最大小区互动平台]
{bf80e5ce-44f9-4954-9ec9-ca5bb86346cd} <http://www.hiu.cn, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\qq\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[硕思闪客名捕]
{E19ADC6E-3909-43E4-9A89-B7B676377EE3} <, N/A>
[精彩图铃]
{EE60714F-AC27-427e-861A-FD60CBDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=163, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[CaiFuCOM Class]
{C1F0024B-8278-4999-B7E6-2718426D9FE6} <C:\Program Files\财富通\caifu.dll, N/A>
[东方快车]
{3EA85E14-887D-4E2F-91E2-3158CE58ED62} <D:\Program Files\!Sunv\DFKC2003\IEBand.dll, 交大铭泰>
[珊瑚虫 工具栏]
{D74EC18E-3DDD-4174-B1B1-949FE3B8366D} <C:\Program Files\Infofo Bar\infofobar.dll, 珊瑚虫工作室 泰格工作室>
[BitComet工具栏]
{3F1ABCDB-A875-46c1-8345-B72A4567E486} <d:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[百度超级搜霸]
{B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[f0f]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\4fd4ntos.dll, N/A>
[搜索栏]
{A1A77F56-C12B-45AF-997E-C1D8505E2E68} <C:\Program Files\搜索栏\eqiso.dll, IE Toolbar>
[sofa]
{B7D3E479-CC68-42B5-A338-B5A0E057163B} <C:\Program Files\SofaToolbar\sofa.dll, IE Toolbar>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[SuperStream Control]
{285C55C4-B32C-4EC0-8539-BBCE97FDF380} <C:\WINDOWS\system32\SUPERS~1.OCX, 盛大网络>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_015.dll, Thunder Networking Technologies,LTD>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[MSTPlayerInstaller Control]
{045ADB92-9635-45CE-B25B-F19F825B0E39} <C:\WINDOWS\DOWNLO~1\MSTPLA~1.OCX, Liztech Co., Ltd>
[MSTWebPlugin Control]
{1552B945-CC5F-11D5-9F52-00001C01C79A} <C:\WINDOWS\MSTPLA~1\MSTWEB~1.OCX, Liztech Co., Ltd>
[Shockwave ActiveX Control]
{166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINDOWS\system32\Macromed\Director\SwDir.dll, Macromedia, Inc.>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[assist]
{1B0E7716-898E-48CC-9690-4E338E8DE1D3} <, N/A>
[Windows Media Player]
hurryhx2 - 2007-2-4 15:17:00
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[MSTWebPlugin Control]
{2841BA0C-6C4B-4549-8948-92C6ECF9378E} <C:\WINDOWS\MSTPLA~1\MSTWEB~1.OCX, Liztech Co., Ltd>
[MemoryManager Class]
{2CE7166E-8BBA-4E76-BA7E-02AB3C573011} <C:\WINDOWS\DOWNLO~1\cytdcli.dll, 北京创原天地科技有限公司>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[]
{3630CC51-C5D1-492B-8B0D-4E03F37A8DBF} <C:\WINDOWS\system32\492bcfsb.dll, N/A>
[IETag Factory]
{38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
[MallObj Class]
{3B30B48F-617D-4F73-A20F-D3D54357F103} <C:\WINDOWS\system32\mallgoo2.dll, 上海奥德易海科技>
[东方快车]
{3EA85E14-887D-4E2F-91E2-3158CE58ED62} <D:\Program Files\!Sunv\DFKC2003\IEBand.dll, 交大铭泰>
[BitComet工具栏]
{3F1ABCDB-A875-46C1-8345-B72A4567E486} <d:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[CBrowseStakeout Class]
{55302805-482E-470E-8A57-6795A1487F90} <D:\KAV2007\KAVAFish.DLL, N/A>
[MSTWebPlugin Control]
{5600F961-5AB3-4A0A-B946-0B954241619D} <C:\WINDOWS\MSTPLA~1\MSTWEB~1.OCX, Liztech Co., Ltd>
[MSTWebPlugin Control]
{5EDEB0F0-1E6F-4E67-9786-E3B6FA7B6F41} <C:\WINDOWS\MSTPLA~1\MSTWEB~1.OCX, Liztech Co., Ltd>
[XBTP07757 Class]
{5F915F24-69C2-4EF0-BF74-8A69E4D28E0B} <C:\PROGRA~1\搜阉索骼栏竆\eqiso.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Innotive Cibrowser Control 1.1]
{70EE0AA4-5A3A-4052-8FFA-2EEDA43F7942} <C:\WINDOWS\system32\CIBROW~1.OCX, Innotive Corp.>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Program Files\Thunder Network\WebThunder\MediaAddin10.dll, Thunder Networking Technologies,LTD>
[BandIE Class]
{77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[MSTWebPlugin Control]
{85705C25-3B30-11D5-BA02-00609718CFFE} <C:\WINDOWS\MSTPLA~1\MSTWEB~1.OCX, Liztech Co., Ltd>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[checksnproj.checksn]
{91141BA1-C977-433C-8B1B-14B3BFBC2AE9} <C:\WINDOWS\Downloaded Program Files\checksnproj.ocx, dy>
[RecordCtl Class]
{9F95BAEE-C07E-11D5-9299-00105A8340B5} <C:\WINDOWS\Downloaded Program Files\LTRecordX.dll, LONG-TRANS TECH. INC.>
[搜索栏]
{A1A77F56-C12B-45AF-997E-C1D8505E2E68} <C:\Program Files\搜索栏\eqiso.dll, IE Toolbar>
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Fc2Boot Class]
{ABA7CC7F-019D-47DB-A0D2-B3C2B3AC1B44} <D:\Program Files\FancyBoxII Games\system\ActiveX\fc2boot.dll, 北京线线通科技开发有限公司>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
[WebDraw Class]
{B234C268-A755-49A1-8A52-C8408A99AD7C} <C:\WINDOWS\system32\photon\support\webutil.dll, >
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[百度超级搜霸]
{B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[sofa]
{B7D3E479-CC68-42B5-A338-B5A0E057163B} <C:\Program Files\SofaToolbar\sofa.dll, IE Toolbar>
[RDS.DataSpace]
hurryhx2 - 2007-2-4 15:17:00
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\system\msadc\msadco.dll, Microsoft Corporation>
[MSTWebPlugin Control]
{C619761B-4C10-41E2-B7C5-18835ADBBC56} <C:\WINDOWS\MSTPLA~1\MSTWEB~1.OCX, Liztech Co., Ltd>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[IEDown Class]
{D0A29C6C-AA71-4423-8C4A-5998B774C448} <C:\WINDOWS\system32\GLIEDown2.dll, 联众公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Microsoft Agent Control 2.0]
{D45FD31B-5C6E-11D1-9EC1-00C04FD7081F} <C:\WINDOWS\msagent\agentctl.dll, Microsoft Corporation>
[珊瑚虫 工具栏]
{D74EC18E-3DDD-4174-B1B1-949FE3B8366D} <C:\Program Files\Infofo Bar\infofobar.dll, 珊瑚虫工作室 泰格工作室>
[f0f]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\4fd4ntos.dll, N/A>
[SWFDecompiler.InternetExplorer]
{E19ADC6E-3909-43E4-9A89-B7B676377EE3} <C:\PROGRA~1\COMMON~1\SOURCE~1\SWFCAT~1\SWFCAT~1.DLL, SourceTec>
[xhkg]
{E2B4F22C-A9D6-47E0-8D66-9397FC844EC1} <C:\PROGRA~1\COMMON~1\dqtp\huxt.dll, >
[Cytd Encipherment Memory]
{F381FC65-D92D-4410-B865-E4E9713994E8} <C:\WINDOWS\DOWNLO~1\cytdcli.dll, 北京创原天地科技有限公司>
[&使用迅雷下载]
<D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<d:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<d:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[全文词典:标注全文...]
<res://d:\Program Files\全文词典\WebDict.dll/211, N/A>
[全文词典:标注选择...]
<res://d:\Program Files\全文词典\WebDict.dll/212, N/A>
[全文词典:网页另存为...]
<res://d:\Program Files\全文词典\WebDict.dll/201, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[添加到百度搜藏]
<http://cang.baidu.com/-/add.html, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\qq\SendMMS.htm, N/A>
[硕思闪客名捕]
<C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm, N/A>
[精彩图铃]
<C:\Program Files\AD4All\link2\phone.htm, N/A>
[豪杰超级解霸V8实时播放]
<D:\Program Files\Herosoft\HeroV8\MPURLGET.HTM, N/A>
[金山毒霸反钓鱼...]
<D:\KAV2007\KAF\ShowSet.htm, N/A>
==================================
正在运行的进程
[PID: 460][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 512][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 536][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4115]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
[c:\program files\internet explorer\plugins\zctyorou.dll] [, 1, 0, 0, 11]
[c:\program files\internet explorer\plugins\fxprzszp.dll] [, 1, 0, 0, 11]
[PID: 580][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 600][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 804][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 916][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1052][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1368][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\BandRes.dll] [, 1, 0, 0, 1]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
hurryhx2 - 2007-2-4 15:18:00
[C:\WINDOWS\system32\mctet.dll] [, 5, 3, 1, 120]
[d:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll] [Kaspersky Lab, 6.0.0.299]
[C:\Program Files\Common Files\Ulead Systems\DVD\USIShex.dll] [Ulead Systems, Inc., 1, 1, 1, 21]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\WINDOWS\system32\wsvbs.dll] [N/A, N/A]
[c:\program files\internet explorer\plugins\zctyorou.dll] [, 1, 0, 0, 11]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[c:\program files\internet explorer\plugins\fxprzszp.dll] [, 1, 0, 0, 11]
[C:\WINDOWS\system32\Kav26.dll] [N/A, N/A]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[PID: 1704][C:\WINDOWS\system32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\WINDOWS\system32\Kav26.dll] [N/A, N/A]
[PID: 1792][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 10.1r11]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\WINDOWS\system32\Kav26.dll] [N/A, N/A]
[d:\Program Files\Thunder Network\WebThunder\WebThunderBHO_015.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
[PID: 1848][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[PID: 384][C:\WINDOWS\System32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[PID: 1580][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[PID: 720][C:\WINDOWS\systom.exe] [N/A, N/A]
[C:\WINDOWS\system32\Kav26.dll] [N/A, N/A]
[PID: 376][d:\Program Files\Thunder Network\WebThunder\WebThunder.exe] [深圳市迅雷网络技术有限公司, 1, 5, 0, 78]
[d:\Program Files\Thunder Network\WebThunder\taskmanage.dll] [Thunder Networking Technologies,LTD, 1, 5, 0, 77]
[d:\Program Files\Thunder Network\WebThunder\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 11, 3, 24]
[d:\Program Files\Thunder Network\WebThunder\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 11, 3, 24]
[d:\Program Files\Thunder Network\WebThunder\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 39]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[d:\Program Files\Thunder Network\WebThunder\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 3, 0, 228]
[d:\Program Files\Thunder Network\WebThunder\UpdateDownload.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
[d:\Program Files\Thunder Network\WebThunder\UpdateExec.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 5]
[d:\Program Files\Thunder Network\WebThunder\iEmbedShell.dll] [ , 1, 0, 0, 14]
[d:\Program Files\Thunder Network\WebThunder\iEmbed07.dll] [ , 3, 1, 0, 58]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\WINDOWS\system32\Kav26.dll] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 10.1r11]
[PID: 1216][d:\Program Files\WinRAR\WinRAR.exe] [N/A, N/A]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\WINDOWS\system32\Kav26.dll] [N/A, N/A]
[PID: 1064][C:\DOCUME~1\xhst\LOCALS~1\Temp\Rar$EX00.593\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\WINDOWS\system32\Kav26.dll] [N/A, N/A]
[PID: 676][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 10.1r11]
[PID: 1980][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\umtcap.dll] [, 5.1.1800.2813]
[C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys] [N/A, N/A]
[PID: 264][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
API HOOK
N/A
==================================
hurryhx2 - 2007-2-4 15:19:00
现在剩下的病毒是第一页图片上的几个文件
清理不掉……
hurryhx2 - 2007-2-4 15:22:00
寻找北方的哥儿 - 2007-2-4 15:34:00
你的IE给修改的不像样子.....唉
hurryhx2 - 2007-2-4 15:38:00
我从来不用ie……用遨游……
另外,刚刚删除了病毒驱动,重起以后又回来了……咋办…………各位大虾
寻找北方的哥儿 - 2007-2-4 15:40:00
叫一下斑主...
hurryhx2 - 2007-2-4 15:52:00
别走啊……
安全防卫 - 2007-2-4 19:21:00
有驱动保护,所有你就算删除了它又会自动恢复,
清除方法参考:
安全模式下.用SRE删除病毒驱动服务,注册表启动项
安全模式下冰刃是不能使用的
用费尔删除文件,或用unlocker1.8.5删除病毒文件
清空IE临时文件夹和temp临时文件夹文件
1
© 2000 - 2026 Rising Corp. Ltd.