瑞星卡卡安全论坛
迭戈阿曼多 - 2007-2-6 21:18:00
AVG查出 我的电脑中了Downloader.AQM 木马 我删了几次都不行 连Temporary Internet Files文件夹也清空了 ,还是不行 ,只要上网就出来,
请问 :它的危害大否 ?而且如何删掉,真是烦死人了!
谢谢!
我是菜鸟 ,初次登陆请大家多多关照!
UFO不幸外人 - 2007-2-6 21:23:00
扫描SRE日志 http://www4.skycn.com/soft/23312.html
迭戈阿曼多 - 2007-2-6 21:28:00
【回复“UFO不幸外人”的帖子】
遵照指示 我先去下载一个装上 然后再说!
迭戈阿曼多 - 2007-2-6 21:49:00
扫描后结果是下面 下一步怎么办 谢谢!
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW
==================================
[/CODE]
上面还有很多扫描结果 需要贴上来吗??????
迭戈阿曼多 - 2007-2-6 21:52:00
另外系统修复一栏 如何使用??????
UFO不幸外人 - 2007-2-6 21:52:00
全部贴上来 一字不拉
迭戈阿曼多 - 2007-2-6 22:00:00
[CODE]
2007-02-06,21:22:17
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<指南针><> [N/A]
<uve5hrqvr><C:\WINDOWS\system.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<bill><rundll32.exe "C:\WINDOWS\system32\winbill070125.dll" mymain> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A]
<WINDVDPatch><CTHELPER.EXE> [Creative Technology Ltd]
<UpdReg><C:\WINDOWS\UpdReg.EXE> [Creative Technology Ltd.]
<Jet Detection><"C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"> [N/A]
<CTStartup><C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run> [Creative Technology Ltd.]
<ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<vptray><C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe> [(Verified)Symantec Corporation]
<DxDialog><C:\WINDOWS\system32\dxdlg32.exe> [Microsoft Corporation]
<!AVG Anti-Spyware><; "C:\Program Files\杀木\avgas.exe" /minimized> [Anti-Malware Development a.s.]
<CalSprite><; C:\Program Files\CalSprite\CalSprite.exe> [SnowFox Studio.]
<StormCodec_Helper><; "C:\Program Files\暴风影音\StormSet.exe" /S /opti> [N/A]
<WebThunder><; D:\下载\迅雷\Web\WebThunder.exe> [深圳市迅雷网络技术有限公司]
<WinampAgent><; C:\Program Files\Winamp\winampa.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINDOWS\system32\ati2sgag.exe><>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
<C:\Program Files\杀木\guard.exe><Anti-Malware Development a.s.>
[卡巴斯基反病毒6.0 / AVP][Stopped/Manual Start]
<"C:\Program Files\卡巴斯基\avp.exe" -r><Kaspersky Lab>
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Network Proxy / ccProxy][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Creative Service for CDROM Access / Creative Service for CDROM Access][Running/Auto Start]
<C:\WINDOWS\system32\CTsvcCDA.exe><Creative Technology Ltd>
[Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
<"C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IS Service / ISSVC][Running/Auto Start]
<"C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe"><Symantec Corporation>
[SavRoam / SavRoam][Stopped/Manual Start]
<"C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
<"C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[Symantec SecurePort / SymSecurePort][Running/Auto Start]
<"C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe"><Symantec Corporation>
[WMDM PMSP Service / WMDM PMSP Service][Running/Auto Start]
<C:\WINDOWS\system32\MsPMSPSv.exe><Microsoft Corporation>
迭戈阿曼多 - 2007-2-6 22:01:00
==================================
驱动程序
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\C:\Program Files\杀木\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[Creative AC3 Software Decoder / ctac32k][Running/Manual Start]
<System32\drivers\ctac32k.sys><Creative Technology Ltd>
[Creative Audio Driver (WDM) / ctaud2k][Running/Manual Start]
<system32\drivers\ctaud2k.sys><Creative Technology Ltd>
[Creative SBLive! Gameport / ctljystk][Stopped/Manual Start]
<system32\DRIVERS\ctljystk.sys><Creative Technology Ltd.>
[Creative Proxy Driver / ctprxy2k][Running/Manual Start]
<System32\drivers\ctprxy2k.sys><Creative Technology Ltd>
[Creative SoundFont Management Device Driver / ctsfm2k][Running/Manual Start]
<System32\drivers\ctsfm2k.sys><Creative Technology Ltd>
[d347bus / d347bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[E-mu Plug-in Architecture Driver / emupia][Running/Manual Start]
<System32\drivers\emupia2k.sys><Creative Technology Ltd>
[EraserUtilDrv10633 / EraserUtilDrv10633][Running/Manual Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10633.sys><Symantec Corporation>
[D-Link DFE-530TX PCI Fast Ethernet Adapter Driver / FETNDIS][Running/Manual Start]
<system32\DRIVERS\dlkfet5b.sys><D-Link>
[Creative Hardware Abstract Layer Driver / ha10kx2k][Running/Manual Start]
<system32\drivers\ha10kx2k.sys><Creative Technology Ltd>
[IdeBusDr / IdeBusDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
[Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\navex15.sys><Symantec Corporation>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Creative OS Services Driver / ossrv][Running/Manual Start]
<system32\drivers\ctoss2k.sys><Creative Technology Ltd.>
[PfModNT / PfModNT][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\PfModNT.sys><Creative Technology Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SAVRT / SAVRT][Running/System Start]
<\??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SPBBCDrv / SPBBCDrv][Stopped/Manual Start]
<\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SYMDNS / SYMDNS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMFW / SYMFW][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMIDSCO / SYMIDSCO][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\SCFIDS~1\20070124.002\symidsco.sys><Symantec Corporation>
[SYMNDIS / SYMNDIS][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[WINIO / WINIO][Stopped/Manual Start]
<\??\H:\winio.sys><N/A>
==================================
浏览器加载项
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\下载\迅雷\ComDlls\XunLeiBHO_004.dll, Thunder Networking Technologies,LTD>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\下载\迅雷\Thunder.exe, Thunder Networking Technologies,LTD>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\下载\迅雷\Web\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\Program Files\Sogou PXP\MMCShell.dll, Sohu.com Inc.>
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\Msjava.dll, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[金山快译(&K)]
{6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <C:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <D:\下载\迅雷\Web\MediaAddin10.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\下载\迅雷\ComDlls\XunLeiBHO_004.dll, Thunder Networking Technologies,LTD>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Microsoft DirectAnimation Control]
{B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} <C:\WINDOWS\system32\danim.dll, Microsoft Corporation>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[&使用迅雷下载]
<D:\下载\迅雷\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\下载\迅雷\Program\GetAllUrl.htm, N/A>
[使用Web迅雷下载]
<D:\下载\迅雷\Web\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<D:\下载\迅雷\Web\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
迭戈阿曼多 - 2007-2-6 22:07:00
=================================
正在运行的进程
[PID: 672][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 732][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 964][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1060][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1172][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1268][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1360][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1444][C:\Program Files\Common Files\Symantec Shared\ccProxy.exe] [Symantec Corporation, 103.5.4.3]
[C:\WINDOWS\system32\SYMREDIR.dll] [Symantec Corporation, 5.5.2.1]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 5.5.2.1]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\DPHTML.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\DPJS.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\DPVBS.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\PFAdBlk.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\PFMisc.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\PFPriv.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\PFSec.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\PxyHTTP.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\DPHTTP.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\PxyIM.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccLogin.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccCharCv.dll] [Symantec Corporation, 103.5.4.3]
[PID: 1500][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.4.3]
[PID: 1528][C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe] [Symantec Corporation, 8.6.1.103]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 5.5.2.1]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\NISRES.DLL] [Symantec Corporation, 8.6.1.103]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.4.3]
[PID: 1588][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\NAVNTUTL.DLL] [Symantec Corporation, 10.0.1.1000]
[D:\下载\迅雷\ComDlls\XunLeiBHO_004.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\杀木\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, N/A]
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\卡巴斯基\shellex.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 1632][C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe] [Symantec Corporation, 5.5.2.1]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 5.5.2.1]
[PID: 1676][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\BB.DLL] [Symantec Corporation, 1,5,1,3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\SPBBCEVT.DLL] [Symantec Corporation, 1,5,1,3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCLOGIN.DLL] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCPXYEVT.DLL] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\SYMANT~1\SYMANT~1\LOGFWDER.DLL] [Symantec Corporation, 8.6.1.103]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 5.5.2.1]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\NisEvt.dll] [Symantec Corporation, 8.6.1.103]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\NAVNTUTL.DLL] [Symantec Corporation, 10.0.1.1000]
[c:\program files\common files\symantec shared\ssc\ScsComms.dll] [Symantec Corporation, 10.0.1.1000]
[C:\WINDOWS\system32\nts.dll] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\WINDOWS\system32\cba.dll] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\WINDOWS\system32\MsgSys.dll] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\WINDOWS\system32\PDS.DLL] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\SNLog.dll] [Symantec Corporation, 8.6.1.103]
[PID: 2000][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1612][C:\Program Files\杀木\guard.exe] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\Program Files\杀木\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[PID: 1704][C:\WINDOWS\system32\CTsvcCDA.exe] [Creative Technology Ltd, 1.0.1.0]
[PID: 1220][C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe] [Symantec Corporation, 10.0.1.1000]
[PID: 228][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[PID: 368][C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe] [Symantec Corporation, 10.0.1.1000]
[C:\WINDOWS\system32\CBA.DLL] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\WINDOWS\system32\MsgSys.dll] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\WINDOWS\system32\NTS.dll] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\WINDOWS\system32\PDS.DLL] [LANDesk Software Ltd., 6.12.0.137 E]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\NAVLU.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\NAVNTUTL.DLL] [Symantec Corporation, 10.0.1.1000]
[c:\program files\common files\symantec shared\ssc\ScsComms.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\I2ldvp3.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccDec.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\decsdk.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.02.12.35]
[C:\Program Files\Common Files\Symantec Shared\ccScan.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 1.4.0.11]
迭戈阿曼多 - 2007-2-6 22:08:00
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\ccEraser.dll] [Symantec Corporation, 106.3.3.2]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefUtDCD.dll] [Symantec Corporation, 3.1.13a.0]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\ecmsvr32.dll] [Symantec Corporation, 71.1.0.11]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\NAVEX32a.DLL] [Symantec Corporation, 20071.1.1.10]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\NAVENG32.DLL] [Symantec Corporation, 20071.1.1.10]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\NAVAP32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\IMail.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\NotesExt.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\vpmsece3.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\SymProtectStorage.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll] [Symantec Corporation, 1,5,1,3]
[C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 10.0.1.1000]
[PID: 512][C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe] [Symantec Corporation, 8.6.1.103]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 5.5.2.1]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\NisEvt.dll] [Symantec Corporation, 8.6.1.103]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 103.5.4.3]
[PID: 612][C:\WINDOWS\system32\MsPMSPSv.exe] [Microsoft Corporation, 7.00.00.1954]
[PID: 1352][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1420][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2100][C:\Program Files\Common Files\Symantec Shared\ccApp.exe] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 103.5.4.3]
[C:\PROGRA~1\SYMANT~1\SYMANT~1\NISPROD.DLL] [Symantec Corporation, 8.6.1.103]
[C:\PROGRA~1\SYMANT~1\SYMANT~1\NISRES.DLL] [Symantec Corporation, 8.6.1.103]
[C:\WINDOWS\system32\SYMREDIR.DLL] [Symantec Corporation, 5.5.2.1]
[C:\PROGRA~1\SYMANT~1\SYMANT~1\NISTRAY.DLL] [Symantec Corporation, 8.6.1.103]
[C:\PROGRA~1\SYMANT~1\SYMANT~1\NISALERT.DLL] [Symantec Corporation, 8.6.1.103]
[C:\WINDOWS\system32\SymNeti.DLL] [Symantec Corporation, 5.5.2.1]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccSet.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccLogin.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\NISLCOM.dll] [Symantec Corporation, 8.6.1.103]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\ccEmlflt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccPxyEvt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavEmail.dll] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymFWAgt.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\SFWAlert.dll] [Symantec Corporation, 8.6.1.103]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\ccFWSetg.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\pRSettg.dll] [N/A, N/A]
[C:\Program Files\Symantec Client Security\Symantec Client Firewall\TLevel.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ccScan.dll] [Symantec Corporation, 103.5.4.3]
[C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 1.4.0.11]
[C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll] [Symantec Corporation, 3.1.13a.0]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\ecmsvr32.dll] [Symantec Corporation, 71.1.0.11]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\NAVEX32a.DLL] [Symantec Corporation, 20071.1.1.10]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070204.009\NAVENG32.DLL] [Symantec Corporation, 20071.1.1.10]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\NAVAP32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.5.0.44]
[PID: 2136][C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 10.0.1.1000]
[C:\PROGRA~1\SYMANT~1\SYMANT~2\NAVNTUTL.DLL] [Symantec Corporation, 10.0.1.1000]
[C:\Program Files\Symantec Client Security\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 10.0.1.1000]
[PID: 2164][C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2164][C:\WINDOWS\system32\dxdlg32.exe] [Microsoft Corporation, 5.03.2800]
[PID: 2192][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3700][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\MagicSet\haokanbar.dll] [Xiang Feng Technology, 2, 2, 0, 1612]
[D:\下载\迅雷\ComDlls\XunLeiBHO_004.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[C:\Program Files\卡巴斯基\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[C:\Program Files\卡巴斯基\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[C:\Program Files\卡巴斯基\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\UNISPIM5.IME] [北京紫光华宇软件股份有限公司, 5.0.0.5076]
[PID: 2968][D:\下载\迅雷\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 5, 1, 241]
[D:\下载\迅雷\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[D:\下载\迅雷\Program\download_interface.dll] [xunlei.com, 1, 0, 0, 1]
[D:\下载\迅雷\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[D:\下载\迅雷\Program\log4cplus.dll] [, 1, 0, 2, 1]
[D:\下载\迅雷\Program\asyn_dns.dll] [N/A, N/A]
[D:\下载\迅雷\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 4]
[D:\下载\迅雷\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 8]
[D:\下载\迅雷\Program\FloatBar.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[D:\下载\迅雷\Program\LiveUpdate.dll] [, 1, 0, 0, 9]
[D:\下载\迅雷\Program\UpdateDownload.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
[D:\下载\迅雷\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[D:\下载\迅雷\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 33]
[D:\下载\迅雷\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 27]
[D:\下载\迅雷\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[D:\下载\迅雷\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 13]
[D:\下载\迅雷\Web\iEmbed07.dll] [ , 3, 1, 0, 58]
[D:\下载\迅雷\Plugins\TingTing\TingTing.dll] [Thunder Networking Technologies,LTD, 1, 1, 1, 12]
[D:\下载\迅雷\Plugins\ExplorerHelper\ExplorerHelper.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\Program Files\卡巴斯基\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[D:\下载\迅雷\Program\msgmanage.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
[C:\Program Files\卡巴斯基\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[C:\Program Files\卡巴斯基\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 2568][F:\下载软件\杀毒软件\瑞星杀毒软件\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[F:\下载软件\杀毒软件\瑞星杀毒软件\sreng2\Plugins\SRECXTMG.SRE] [Smallfrogs Studio, 1, 5, 0, 55]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW
==================================
[/CODE]
迭戈阿曼多 - 2007-2-6 22:10:00
发完了 这个网站太麻烦 怎么老是验证码不对 明明对吗!
UFO不幸外人 - 2007-2-6 22:14:00
打开冰刃
在注册表中 打开[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run删除
<指南针><> [N/A]
<uve5hrqvr><C:\WINDOWS\system.exe> [N/A]
打开HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run删除
<bill><rundll32.exe "C:\WINDOWS\system32\winbill070125.dll" mymain> [N/A]
打开文件强制删除
C:\WINDOWS\system32\winbill070125.dll
C:\WINDOWS\system.exe
以下是我的怀疑
[WMDM PMSP Service / WMDM PMSP Service][Running/Auto Start]
<C:\WINDOWS\system32\MsPMSPSv.exe><Microsoft Corporation>
DxDialog><C:\WINDOWS\system32\dxdlg32.exe>
<WINDVDPatch><CTHELPER.EXE> [Creative Technology Ltd]
<UpdReg><C:\WINDOWS\UpdReg.EXE>文件是你安装的软件么
迭戈阿曼多 - 2007-2-6 22:20:00
怎么办呀 我在等 谢谢!
迭戈阿曼多 - 2007-2-6 22:27:00
指南针不能动 <UpdReg><C:\WINDOWS\UpdReg.EXE>文件是你安装的软件么 是我装的 与创新5.1有关 ,
冰刃 我有 但没用过 高手指导 我去试试!
我装有unlocker1.8.5 可以强删文件夹!
谢谢!
UFO不幸外人 - 2007-2-6 22:42:00
打开冰刃
在注册表中 打开[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run删除
<指南针><> [N/A]
<uve5hrqvr><C:\WINDOWS\system.exe> [N/A]
打开HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run删除
<bill><rundll32.exe "C:\WINDOWS\system32\winbill070125.dll" mymain> [N/A]
打开文件强制删除
C:\WINDOWS\system32\winbill070125.dll
C:\WINDOWS\system.exe
下载地址 http://www.ttian.net/website/2005/0829/391.html
指南针删除了吧,那个已经为空项了 没有意义
软件当然不会因为删除这个而影响正常启动
迭戈阿曼多 - 2007-2-6 23:16:00
老大 没有这个文件呀????、
WINDOWS\system32\winbill070125.dll 搜不到!
里面我也找了一遍 没有发现它
见鬼了!
westbeck - 2007-2-6 23:19:00
请再扫份日志
westbeck - 2007-2-6 23:19:00
请再扫份日志
sanjingshou - 2007-2-6 23:23:00
安全模式下打开我的电脑,单击-工具-文件夹选项-查看-勾选隐藏文件和文件夹,显示所有文件
删除文件:C:\WINDOWS\system32\winbill070125.dll
迭戈阿曼多 - 2007-2-6 23:46:00
安全模式下打开我的电脑,单击-工具-文件夹选项-查看-勾选隐藏文件和文件夹,显示所有文件
照办了 还是没有
C:\WINDOWS\system32\winbill070125.dll
迭戈阿曼多 - 2007-2-6 23:53:00
我刚才avg扫描了 Downloader.AQM 还在我的文件夹里 Local Settings - Temporary Internet Files
杀死后必须清空文件夹才行 但只要上网 就又会出来!
1
© 2000 - 2026 Rising Corp. Ltd.