瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 这论坛怎么了?
WHY520 - 2007-2-18 18:36:00


原日志名:
斑主救救我吧....跪谢~~~附日志



启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <Super Rabbit IEPro><F:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <KavPFW><"E:\Program Files\KPFW32.EXE">  [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <ATIPTA><"C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe">  [ATI Technologies, Inc.]
    <HControl><C:\WINDOWS\ATK0100\HControl.exe>  [(Verified)]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <zzpefr74><C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\zzpefr74.dll,DllCanUnloadNow>  [Microsoft Corporation]
    <BigDogPath><C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera (ZC0301PL)>  [N/A]
    <Syetwys><C:\WINDOWS\system32\algestese.exe>  []
    <dfsf><RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv>  [N/A]
    <powerword 2007><"D:\模拟器\新建文件夹\Powerword 2007\xdict.exe" -s -nosplash>  [Kingsoft Co, Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WebSecurity><C:\WINDOWS\system32\PvSec.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg]
    <WinlogonNotify: cryptimg><cryptig.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{78BF3960-61F0-4F4E-825D-3554FA61E847}><C:\WINDOWS\system32\wmpkn.dll>  [N/A]
    <{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\WsReource.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [N/A]
    <StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[Event Service / AtHome]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\cxwchi13.dll><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[EvtEng / EvtEng]
  <C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc]
  <"E:\Program Files\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc]
  <"E:\Program Files\KWatch.EXE"><Kingsoft Corporation>
[Transaction Provisioning Service / mitaozi]
  <C:\WINDOWS\system32\0.exe><N/A>
[OwnershipProtocol / OwnershipProtocol]
  <C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe><Intel Corporation>
[RegSrvc / RegSrvc]
  <C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Remote Access Connection Management / Remote Access Connection Management]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ncxml.dll><>
[Spectrum24 Event Monitor / S24EventMonitor]
  <C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation>
[NT Data Provider / SDTSTA]
  <C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\BVGCMD02.DLL,Export 1087><Microsoft Corporation>
WHY520 - 2007-2-18 18:37:00
[Vsn vhux Service / vhux]
  <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\bnxa\iueh.dll,Service><Microsoft Corporation>
[Visual Studio Analyzer RPC bridge / Visual Studio Analyzer RPC bridge]
  <F:\Temp\Tools\VS-Ent98\Vanalyzr\varpc.exe><N/A>
[Computer Storage / WIDETS]
  <C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>

==================================
驱动程序
[a320raid / a320raid]
  <\SystemRoot\System32\DRIVERS\a320raid.sys><Adaptec, Inc.>
[AAC / AAC]
  <\SystemRoot\System32\DRIVERS\AAC.SYS><Adaptec, Inc.>
[aar1210 / aar1210]
  <\SystemRoot\System32\DRIVERS\aar1210.sys><Adaptec, Inc.>
[abp480n5 / abp480n5]
  <\SystemRoot\System32\DRIVERS\abp480n5.sys><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[adpu160m / adpu160m]
  <\SystemRoot\System32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[adpu320 / adpu320]
  <\SystemRoot\System32\DRIVERS\adpu320.sys><Adaptec, Inc.>
[ACARD AEC6210UF UltraDMA33 Controller / aec6210]
  <\SystemRoot\System32\DRIVERS\aec6210.sys><ACARD Technology Corp.>
[ACARD AEC6260 UltraDMA-66 Controller / aec6260]
  <\SystemRoot\System32\DRIVERS\aec6260.sys><ACARD Technology Corp.>
[aec6280 / aec6280]
  <\SystemRoot\System32\DRIVERS\aec6280.sys><ACARD Technology Corp.>
[AEC6290 / AEC6290]
  <\SystemRoot\System32\DRIVERS\AEC6290.SYS><ACARD Technology Corp.>
[AEC67160 / AEC67160]
  <\SystemRoot\System32\DRIVERS\AEC67160.SYS><ACARD Technology Corp.>
[AEC671X / AEC671X]
  <\SystemRoot\System32\DRIVERS\AEC671X.SYS><ACARD Technology Corp.>
[AEC6880 / AEC6880]
  <\SystemRoot\System32\DRIVERS\AEC6880.SYS><ACARD Technology Corp.>
[AEC6890 / AEC6890]
  <\SystemRoot\System32\DRIVERS\AEC6890.sys><ACARD Technology Corp.>
[aec68x5 / aec68x5]
  <\SystemRoot\System32\DRIVERS\aec68x5.sys><ACARD Technology Corp.>
[AEGIS Protocol (IEEE 802.1x) v3.2.0.3 / AegisP]
  <system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[Aha154x / Aha154x]
  <\SystemRoot\System32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2]
  <\SystemRoot\System32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx]
  <\SystemRoot\System32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde]
  <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[amdk5 / amdk5]
  <\??\C:\WINDOWS\system32\drivers\amdk5.sys><N/A>
[AMD K8 Processor Driver / AmdK8]
  <System32\DRIVERS\amdk8.sys><Microsoft Corporation>
WHY520 - 2007-2-18 18:37:00
[arc / arc]
  <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
[asc / asc]
  <\SystemRoot\System32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3550 / asc3550]
  <\SystemRoot\System32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ast / ast]
  <\??\C:\WINDOWS\system32\drivers\ast.sys><N/A>
[ati2mtag / ati2mtag]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[atmsig / atmsig]
  <\??\C:\WINDOWS\system32\drivers\atmsig.sys><N/A>
[cd20xrnt / cd20xrnt]
  <C:\WINDOWS\SYSTEM32\DRIVERS\cd20xrnt.SYS><Microsoft Corporation>
[cdawdm / cdawdm]
  <\SystemRoot\system32\DRIVERS\CDAWDM.sys><N/A>
[CmdIde / CmdIde]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[C-Media WDM Audio Interface / cmuda]
  <system32\drivers\cmuda.sys><C-Media Inc>
[dac2w2k / dac2w2k]
  <\SystemRoot\System32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o]
  <\SystemRoot\System32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[elxstor / elxstor]
  <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
[erqikd0 / erqikd00]
  <\SystemRoot\System32\DRIVERS\erqikd00.sys><Microsoft Corporation>
[FASTSX / FASTSX]
  <\SystemRoot\System32\DRIVERS\FASTSX.SYS><Promise Technology, Inc.>
[fasttrak / fasttrak]
  <\SystemRoot\System32\DRIVERS\fasttrak.sys><Promise Technology, Inc.>
[fasttx2k / fasttx2k]
  <\SystemRoot\System32\DRIVERS\fasttx2k.sys><Promise Technology, Inc.>
[fasttx2k2 / fasttx2k2]
  <\SystemRoot\System32\DRIVERS\fasttx2k2.sys><Promise Technology, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[ffpbek / ffpbek]
  <\??\C:\WINDOWS\system32\drivers\ffpbek.sys><Microsoft Corporation>
[gfspjjk / gfspjjkx]
  <\SystemRoot\System32\DRIVERS\gfspjjkx.sys><Microsoft Corporation>
[HpCISSs / HpCISSs]
  <\SystemRoot\system32\drivers\hpcisss.sys><Hewlett-Packard Company>
[Hpt366 / Hpt366]
  <\SystemRoot\System32\DRIVERS\Hpt366.sys><Microsoft Corporation>
[HPT371 / HPT371]
  <\SystemRoot\System32\DRIVERS\HPT371.sys><HighPoint Technologies, Inc.>
[hpt374 / hpt374]
  <\SystemRoot\System32\DRIVERS\hpt374.sys><HighPoint Technologies, Inc.>
[hpt3xx / hpt3xx]
  <\SystemRoot\System32\DRIVERS\hpt3xx.sys><HighPoint Technologies, Inc.>
[hptmv / hptmv]
  <\SystemRoot\System32\DRIVERS\hptmv.sys><HighPoint Technologies, Inc.>
[hptpro / hptpro]
  <\SystemRoot\System32\DRIVERS\hptpro.sys><HighPoint Technologies, Inc.>
[HSFHWICH / HSFHWICH]
  <system32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP]
  <system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
WHY520 - 2007-2-18 18:37:00
[HTTP / HTTP]
  <System32\Drivers\HTTP.sys><N/A>
[Intel Integrated RAID / iaStor]
  <\SystemRoot\system32\drivers\iaStor.sys><Intel Corporation>
[iirsp / iirsp]
  <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
[ini910u / ini910u]
  <\SystemRoot\System32\DRIVERS\ini910u.sys><Microsoft Corporation>
[ITERAID_Service_Install / iteraid]
  <\SystemRoot\System32\DRIVERS\iteraid.sys><Integrated Technology Express, Inc.>
[jscont2 / jscont22]
  <\SystemRoot\System32\DRIVERS\jscont22.sys><N/A>
[KNetWch / KNetWch]
  <\??\E:\Program Files\KNetWch.SYS><Kingsoft Corporation>
[KWatch3 / KWatch3]
  <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[LanPort / LanPort]
  <\??\C:\WINDOWS\system32\drivers\LanPort.sys><N/A>
[LSI_SAS / LSI_SAS]
  <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Logic>
[LSI_SCSI / LSI_SCSI]
  <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Logic>
[m5228 / m5228]
  <\SystemRoot\System32\DRIVERS\m5228.sys><ALi Corporation.>
[m5281 / m5281]
  <\SystemRoot\system32\drivers\m5281.sys><ALi Corporation>
[mdmxsdk / mdmxsdk]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[MegaIDE / MegaIDE]
  <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[megasas / megasas]
  <\SystemRoot\system32\drivers\megasas.sys><LSI Logic Corporation>
[mffalmj / mffalmj]
  <\SystemRoot\system32\drivers\mffalmj.sys><N/A>
[mraid2k / mraid2k]
  <\SystemRoot\System32\DRIVERS\mraid2k.sys><American Megatrends, Inc.>
[mraid35x / mraid35x]
  <\SystemRoot\System32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[ATK0100 ACPI UTILITY / MTsensor]
  <system32\DRIVERS\ATKACPI.sys><>
[nfrd960 / nfrd960]
  <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
[npkcrypt / npkcrypt]
  <\??\E:\新建文件夹 (3)\QQ\npkcrypt.sys><N/A>
[npkcusb / npkcusb]
  <\??\E:\新建文件夹 (3)\QQ\npkcusb.sys><INCA Internet Co., Ltd.>
[nv / nv]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Intel SCSI Controller / NvAtaBus]
  <\SystemRoot\System32\DRIVERS\NVATABUS.SYS><NVIDIA Corporation>
[NVIDIA nForce(tm) RAID Class Driver / nvraid]
  <\SystemRoot\system32\DRIVERS\nvraid.sys><NVIDIA Corporation>
[nwlnksipx / nwlnksipx]
  <\??\C:\WINDOWS\system32\drivers\nwlnksipx.sys><Microsoft Corporation>
WHY520 - 2007-2-18 18:38:00
[PNP649R / PNP649R]
  <\SystemRoot\System32\DRIVERS\PNP649R.SYS><CMD Technology, Inc.>
[SiI 680 ATA Controller / Pnp680]
  <\SystemRoot\System32\DRIVERS\pnp680.sys><Silicon Image, Inc.>
[Silicon Image SiI 0680 Medley Raid Controller / Pnp680r]
  <\SystemRoot\System32\DRIVERS\pnp680r.sys><Silicon Image, Inc>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ql1080 / ql1080]
  <\SystemRoot\System32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt]
  <\SystemRoot\System32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160]
  <\SystemRoot\System32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280]
  <\SystemRoot\System32\DRIVERS\ql1280.sys><QLogic Corporation>
[QLogic Fibre Channel SCSI Miniport Driver / ql2300]
  <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
[QuakeDRV / QuakeDRV]
  <\SystemRoot\system32\DRIVERS\quakedrv.sys><N/A>
[RAIDSRC / RAIDSRC]
  <\SystemRoot\System32\DRIVERS\RAIDSRC.SYS><Intel/ICP>
[Ricoh MediaCard Driver / rmedia]
  <\SystemRoot\system32\DRIVERS\rmedia.sys><REDC>
[S150SX8 / S150SX8]
  <\SystemRoot\System32\DRIVERS\S150SX8.SYS><Promise Technology, Inc.>
[WLAN 传输 / s24trans]
  <system32\DRIVERS\s24trans.sys><Intel Corporation>
[sdpnusp / sdpnuspc]
  <\SystemRoot\System32\DRIVERS\sdpnuspc.sys><Microsoft Corporation>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[SiI-3512 SATALink Controller / SI3112]
  <\SystemRoot\System32\DRIVERS\SI3112.sys><Silicon Image, Inc.>
[Silicon Image SiI 3512 SATARaid Controller / SI3112r]
  <\SystemRoot\system32\drivers\SI3112r.sys><Silicon Image, Inc>
[SiI-3114 SATALink Controller / SI3114]
  <\SystemRoot\System32\DRIVERS\SI3114.sys><Silicon Image, Inc.>
[SiI-3114 SATARaid Controller / SI3114r]
  <\SystemRoot\System32\DRIVERS\SI3114R.sys><Silicon Image, Inc>
[SiI-3124 SATALink Controller / SI3124]
  <\SystemRoot\System32\DRIVERS\SI3124.sys><Silicon Image, Inc.>
[SiI-3124 SATARaid Controller / SI3124r]
  <\SystemRoot\System32\DRIVERS\SI3124R.sys><Silicon Image, Inc>
[SATALink driver accelerator / SiFilter]
  <\SystemRoot\System32\DRIVERS\SiWinAcc.sys><Silicon Image, Inc.>
[SISIDE / SISIDE]
  <\SystemRoot\System32\DRIVERS\SISIDE.SYS><Silicon Integrated Systems Corp.>
[SiSRaid / SiSRaid]
  <\SystemRoot\System32\DRIVERS\SiSRaid.sys><Silicon Integrated Systems>
WHY520 - 2007-2-18 18:38:00
[SiSRaid1 / SiSRaid1]
  <\SystemRoot\System32\DRIVERS\SiSRaid1.sys><Silicon Integrated Systems>
[SISRAIDS / SISRAIDS]
  <\SystemRoot\System32\DRIVERS\SISRAIDS.SYS><Silicon Integrated Systems Corp>
[Sparrow / Sparrow]
  <\SystemRoot\System32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[sptrak / sptrak]
  <\SystemRoot\System32\DRIVERS\sptrak.sys><Promise Technology, Inc.>
[symc810 / symc810]
  <\SystemRoot\System32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx]
  <\SystemRoot\System32\DRIVERS\symc8xx.sys><LSI Logic>
[SYMMPI / SYMMPI]
  <\SystemRoot\System32\DRIVERS\SYMMPI.SYS><LSI Logic>
[sym_hi / sym_hi]
  <\SystemRoot\System32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3]
  <\SystemRoot\System32\DRIVERS\sym_u3.sys><LSI Logic>
[TCP/IP Protocol Driver / Tcpip]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[tjrhdgb / tjrhdgbu]
  <\SystemRoot\System32\DRIVERS\tjrhdgbu.sys><Microsoft Corporation>
[TosIde / TosIde]
  <\SystemRoot\System32\DRIVERS\toside.sys><Microsoft Corporation>
[UlSata / UlSata]
  <\SystemRoot\System32\DRIVERS\ulsata.sys><Promise Technology, Inc.>
[ULSATAS / ULSATAS]
  <\SystemRoot\System32\DRIVERS\ULSATAS.SYS><Promise Technology, Inc.>
[ultra / ultra]
  <\SystemRoot\System32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[uphkfla / uphkfla]
  <\SystemRoot\system32\drivers\uphkfla.sys><N/A>
[VCD VNC Virtual Network Adapter / vcddev]
  <system32\DRIVERS\vcdvnic.sys><VNN B.J.>
[ViaIde / ViaIde]
  <\SystemRoot\System32\DRIVERS\viaide.sys><Microsoft Corporation>
[viamraid / viamraid]
  <\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[VIA ATA/ATAPI Host Controller / viapdsk]
  <\SystemRoot\System32\DRIVERS\viapdsk.sys><VIA Technologies, Inc.>
[viaraid / viaraid]
  <\SystemRoot\System32\DRIVERS\viaraid.sys><VIA Technologies inc,.ltd>
[viasraid / viasraid]
  <\SystemRoot\system32\drivers\viasraid.sys><VIA Technologies inc,.ltd>
[vmscsi / vmscsi]
  <\SystemRoot\system32\drivers\vmscsi.sys><VMware, Inc.>
[用于 Windows XP 的英特尔(R) PRO/无线 2200BG 网络连接驱动程序 / w29n51]
  <system32\DRIVERS\w29n51.sys><Intel? Corporation>
[winachsf / winachsf]
  <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[wspipe / wspipe]
  <\??\C:\WINDOWS\system32\drivers\wspipe.sys><N/A>
WHY520 - 2007-2-18 18:39:00
==================================
浏览器加载项
[veru]
  {55EC3AA6-7092-4274-948A-62D1E9BF414D} <C:\PROGRA~1\bnxa\frbe.dll, >
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <F:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[e17]
  {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\484cntos.dll, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\新建文件夹 (3)\QQ\QQ.EXE, TENCENT>
[CaiFuCOM Class]
  {C1F0024B-8278-4999-B7E6-2718426D9FE6} <C:\Program Files\财富通\caifu.dll, N/A>
[e17]
  {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\484cntos.dll, N/A>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <F:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[]
  {2BA15999-5AE3-45A0-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\45a0ntos.dll, N/A>
[veru]
  {55EC3AA6-7092-4274-948A-62D1E9BF414D} <C:\PROGRA~1\bnxa\frbe.dll, >
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <F:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[e17]
  {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\484cntos.dll, N/A>
[&使用迅雷下载]
  <E:\新建文件夹\xunlei\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <E:\新建文件夹\xunlei\Thunder\Program\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
  <E:\新建文件夹 (3)\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\新建文件夹 (3)\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\新建文件夹 (3)\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 488][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 560][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 572][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 732][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4119]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2497]
[PID: 744][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 884][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
WHY520 - 2007-2-18 18:39:00
[c:\windows\system32\ncxml.dll]  [, 1, 0, 0, 1]
[PID: 1004][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 9, 0, 2, 11]
[PID: 1032][C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe]  [Intel Corporation , 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 9, 0, 2, 11]
[PID: 1084][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1168][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1364][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1608][E:\Program Files\KPfwSvc.EXE]  [Kingsoft Corporation, 2005, 9, 5, 28]
[PID: 1620][C:\WINDOWS\system32\0.exe]  [N/A, N/A]
[PID: 1652][C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [N/A, N/A]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 9, 0, 2, 11]
[PID: 1676][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe]  [Intel Corporation, 9, 0, 2, 11]
[PID: 1724][C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE]  [Microsoft Corporation, 5.00.2134.1]
[PID: 1788][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1808][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1844][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\bnxa\iueh.dll]  [, 1, 2, 0, 8]
[PID: 980][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\yk_urh.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\xf_kjv.dll]  [N/A, N/A]
    [C:\WINDOWS\system\Mvvp.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\wmpkn.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\WsReource.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\PvSec.dll]  [, 5, 1, 100, 2500]
    [C:\PROGRA~1\bnxa\frbe.dll]  [, 1, 2, 0, 8]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [E:\Program Files\KAVEXT.DLL]  [Kingsoft Corporation, 2005, 8, 5, 16]
    [E:\新建文件夹 (3)\QQ\qdshm.dll]  [, 1, 0, 101, 20]
[PID: 1904][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5166]
    [C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.5166]
    [C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  [ATI Technologies, Inc., 6.14.10.5166]
    [C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  [ATI Technologies, Inc., 6.14.10.5166]
[PID: 1716][C:\WINDOWS\ATK0100\HControl.exe]  [, 1043, 2, 15, 51]
    [C:\WINDOWS\ATK0100\CMSSC.dll]  [N/A, N/A]
    [C:\WINDOWS\ATK0100\inter_f2.dll]  [ATK, 1043, 2, 15, 46]
    [C:\WINDOWS\ATK0100\ATKWLIOC.DLL]  [ACTIONTEC Electronics,Inc, 2.01.02]
    [C:\WINDOWS\ATK0100\SiSPkt.dll]  [Silicon Integrated Systems Corp., 1, 0, 0, 45]
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [N/A, N/A]
WHY520 - 2007-2-18 18:40:00
[C:\Program Files\Intel\Wireless\Bin\C8021CHS.dll]  [Intel Corporation, 9, 0, 2, 11]
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  [Intel Corporation, 9, 0, 2, 11]
[PID: 1924][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3427]
[PID: 1872][C:\WINDOWS\VM_STI.EXE]  [Vimicro, 4, 2, 1124, 6]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
[PID: 296][C:\WINDOWS\system32\algestese.exe]  [, ]
[PID: 388][D:\模拟器\新建文件夹\Powerword 2007\xdict.exe]  [Kingsoft Co, Ltd., 10, 0, 0, 1]
    [D:\模拟器\新建文件夹\Powerword 2007\ITextOut.dll]  [Kingsoft, 1, 1, 0, 1]
    [D:\模拟器\新建文件夹\Powerword 2007\xfile.dll]  [N/A, N/A]
    [D:\模拟器\新建文件夹\Powerword 2007\KPic10.dll]  [N/A, N/A]
    [D:\模拟器\新建文件夹\Powerword 2007\ijl11.dll]  [Intel Corporation, 1.1.2]
    [D:\模拟器\新建文件夹\Powerword 2007\toTTSEngine50.dll]  [Kingsoft Corporation, 1, 0, 0, 1]
    [D:\模拟器\新建文件夹\Powerword 2007\NormGrab.DLL]  [Kingsoft Co, Ltd., 9, 0, 0, 1]
    [D:\模拟器\新建文件夹\Powerword 2007\AccountActivate.dll]  [N/A, N/A]
    [D:\模拟器\新建文件夹\Powerword 2007\statistics.dll]  [N/A, N/A]
    [D:\模拟器\新建文件夹\Powerword 2007\DBCore10.dll]  [Kingsoft  Corp., 1, 5, 0, 1]
    [D:\模拟器\新建文件夹\Powerword 2007\XdictGrb.dll]  [Kingsoft Co, Ltd., 9, 0, 0, 2]
    [D:\模拟器\新建文件夹\Powerword 2007\DictionaryManager.dll]  [, 1, 0, 0, 1]
    [D:\模拟器\新建文件夹\Powerword 2007\Xml2Xdata.dll]  [, 1, 0, 0, 1]
    [D:\模拟器\新建文件夹\Powerword 2007\KAVPassport.DLL]  [Kingsoft Corporation, 2005, 9, 27, 0]
[PID: 404][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1276][E:\Program Files\KPFW32.EXE]  [Kingsoft Corporation, 2006, 1, 17, 609]
    [E:\Program Files\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [E:\Program Files\KAConfig.DLL]  [Kingsoft Corporation, 2005, 3, 23, 30]
    [E:\Program Files\FiltList.dll]  [N/A, N/A]
    [E:\Program Files\KAVPassp.DLL]  [Kingsoft Corporation, 2006, 5, 26, 246]
    [E:\Program Files\KAEPlat.DLL]  [Kingsoft Corp., 2005, 12, 29, 56]
    [E:\Program Files\KAEMem.DAT]  [Kingsoft, 2006, 4, 12, 13]
    [E:\Program Files\KAEUnpack.DAT]  [Kingsoft Corp., 2006, 5, 11, 34]
[PID: 2080][C:\WINDOWS\ATK0100\ATKOSD.exe]  [, 1043, 2, 15, 51]
[PID: 3168][C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3204][C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3272][C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2092][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
[PID: 2204][C:\DOCUME~1\new\LOCALS~1\Temp\Rar$EX00.276\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
WHY520 - 2007-2-18 18:40:00
==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
New.net UDP Chain
    C:\Program Files\NewDotNet\newdotnet7_22.dll(N/A, N/A)
New.net TCP Chain
    C:\Program Files\NewDotNet\newdotnet7_22.dll(N/A, N/A)
MSAFD Tcpip [TCP/IP]
    c:\windows\rsvpsp.dll(N/A, N/A)
MSAFD Tcpip [UDP/IP]
    c:\windows\rsvpsp.dll(N/A, N/A)
MSAFD Tcpip [RAW/IP]
    c:\windows\rsvpsp.dll(N/A, N/A)
New.net TCP Filter
    C:\Program Files\NewDotNet\newdotnet7_22.dll(N/A, N/A)
New.net UDP Filter
    C:\Program Files\NewDotNet\newdotnet7_22.dll(N/A, N/A)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
WHY520 - 2007-2-19 10:11:00
为什么没人帮助我啊?555555555555555555555555
WHY520 - 2007-2-19 11:04:00
会不会有把键盘都搞坏的病毒?我现在有几个键盘打不出字了,打出来的变成数字了,到底是键盘坏了还是病毒?
WHY520 - 2007-2-23 14:08:00
我发了那么久说了那么多,怎么没有一个人愿意帮助我的,虽然我也知道,大家很忙,可是我想,我用的是正版的瑞星,我有问题了,找到这儿,如果找到这儿没用的话,我不知道还能到那儿去找解决的办法.....很想念红夜鬼,他怎么不见了?
logicl - 2007-2-23 14:16:00
引用:
【WHY520的贴子】会不会有把键盘都搞坏的病毒?我现在有几个键盘打不出字了,打出来的变成数字了,到底是键盘坏了还是病毒?
………………


刚看到帖子.
这个不会,你用的是笔记本,因为它没有数字键盘,所以它的数字键是和字母在一起的.它是由一个按键控制的.(具体是哪个我记不得,好象Fn+..),你在键盘上找一下.

日志我再看一下
WHY520 - 2007-2-23 14:26:00
谢谢....我的是笔记本,键盘没问题了....再次谢谢~~
logicl - 2007-2-23 14:35:00
声明:因为个人能力有限,你用的笔记本,有很多驱动我没有遇到过,所以在下面的分析中,如果你确认哪个文件是你电脑驱动不是病毒的话,那你就别动它!!
如果看不懂的话,可以先看一下这张SREng如何使用的帖子http://forum.ikaka.com/topic.asp?board=28&artid=8270267
1. 杀毒前关闭系统还原(Win2000系统可以忽略):右键 我的电脑 ,属性,系统还原,在所有驱动器上关闭系统还原 打勾即可。
清除IE的临时文件:打开IE 点工具-->Internet选项 : Internet临时文件,点“删除文件”按钮 ,将 删除所有脱机内容 打勾,点确定删除。
2.将下面启动项删除:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Syetwys><C:\WINDOWS\system32\algestese.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{78BF3960-61F0-4F4E-825D-3554FA61E847}><C:\WINDOWS\system32\wmpkn.dll>
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\WsReource.dll>

3.用PowerRMV(勾选杀灭文件再生成)删除下面文件:
C:\WINDOWS\system32\0.exe
C:\WINDOWS\system32\algestese.exe
C:\WINDOWS\system32\PvSec.dl
C:\WINDOWS\system32\wmpkn.dll
C:\WINDOWS\system32\WsReource.dll
C:\WINDOWS\system32\ncxml.dll
C:\WINDOWS\System32\Drivers\HTTP.sy
C:\WINDOWS\system32\drivers\amdk5.sys
C:\WINDOWS\system32\drivers\wspipe.sys

4.删除下面服务
[Transaction Provisioning Service / mitaozi]
<C:\WINDOWS\system32\0.exe>
[Remote Access Connection Management / Remote Access Connection Management]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ncxml.dll>

5.删除下面驱动程序
amdk5 / amdk5]
<\??\C:\WINDOWS\system32\drivers\amdk5.sys>
[ast / ast]
<\??\C:\WINDOWS\system32\drivers\ast.sys>
[HTTP / HTTP]
<System32\Drivers\HTTP.sys>
[jscont2 / jscont22]
<\SystemRoot\System32\DRIVERS\jscont22.sys>
[mffalmj / mffalmj]
<\SystemRoot\system32\drivers\mffalmj.sys>
[wspipe / wspipe]
<\??\C:\WINDOWS\system32\drivers\wspipe.sys>

6.用SREng重置winsock ,修复所有文件关联
WHY520 - 2007-2-23 14:39:00
跪谢了,我去试试....^_^
baohe - 2007-2-23 15:47:00
【回复“WHY520”的帖子】
1、结束下列病毒进程:
[PID: 1620][C:\WINDOWS\system32\0.exe] [N/A, N/A]
[PID: 1724][C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE] [Microsoft Corporation, 5.00.2134.1]
2、用 IceSword禁止进程创建,然后强制卸除插入Explorer.EXE进程中的病毒模块:
[PID: 980][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\yk_urh.dll] [N/A, N/A]
[C:\WINDOWS\system32\xf_kjv.dll] [N/A, N/A]
[C:\WINDOWS\system\Mvvp.dll] [N/A, N/A]
[C:\WINDOWS\system32\wmpkn.dll] [N/A, N/A]
[C:\WINDOWS\system32\WsReource.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\PvSec.dll] [, 5, 1, 100, 2500]
[C:\PROGRA~1\bnxa\frbe.dll] [, 1, 2, 0, 8]

3、删除下列启动项、服务项、驱动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<zzpefr74><C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\zzpefr74.dll,DllCanUnloadNow> [Microsoft Corporation]
<Syetwys><C:\WINDOWS\system32\algestese.exe> []
<dfsf><RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{78BF3960-61F0-4F4E-825D-3554FA61E847}><C:\WINDOWS\system32\wmpkn.dll> [N/A]
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\WsReource.dll> []
服务
[Event Service / AtHome]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\cxwchi13.dll><Microsoft Corporation>
[Transaction Provisioning Service / mitaozi]
<C:\WINDOWS\system32\0.exe><N/A>
[Remote Access Connection Management / Remote Access Connection Management]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ncxml.dll><>
[NT Data Provider / SDTSTA]
<C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\BVGCMD02.DLL,Export 1087><Microsoft Corporation>
[Computer Storage / WIDETS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>
驱动
[amdk5 / amdk5]
<\??\C:\WINDOWS\system32\drivers\amdk5.sys><N/A>
[HTTP / HTTP]
<System32\Drivers\HTTP.sys><N/A>
[jscont2 / jscont22]
<\SystemRoot\System32\DRIVERS\jscont22.sys><N/A>
[LanPort / LanPort]
<\??\C:\WINDOWS\system32\drivers\LanPort.sys><N/A>
[mffalmj / mffalmj]
<\SystemRoot\system32\drivers\mffalmj.sys><N/A>
[nwlnksipx / nwlnksipx]
<\??\C:\WINDOWS\system32\drivers\nwlnksipx.sys><Microsoft Corporation>
[uphkfla / uphkfla]
<\SystemRoot\system32\drivers\uphkfla.sys><N/A>
[wspipe / wspipe]
<\??\C:\WINDOWS\system32\drivers\wspipe.sys><N/A>

4、删除下列浏览器加载项:
[e17]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\484cntos.dll, N/A>
[]
{2BA15999-5AE3-45A0-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\45a0ntos.dll, N/A>
[veru]
{55EC3AA6-7092-4274-948A-62D1E9BF414D} <C:\PROGRA~1\bnxa\frbe.dll, >

5、删除下列病毒文件:
C:\WINDOWS\system32\0.exe
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
C:\WINDOWS\system32\yk_urh.dll
C:\WINDOWS\system32\xf_kjv.dll
C:\WINDOWS\system\Mvvp.dll
C:\WINDOWS\system32\wmpkn.dll
C:\WINDOWS\system32\WsReource.dll
C:\WINDOWS\system32\PvSec.dll
C:\PROGRA~1\bnxa\frbe.dll
C:\WINDOWS\system32\zzpefr74.dll
C:\WINDOWS\system32\algestese.exe
C:\WINDOWS\system\Mvvp.dll
C:\WINDOWS\system32\PvSec.dll
C:\WINDOWS\system32\WsReource.dll
C:\WINDOWS\system32\cxwchi13.dll
C:\WINDOWS\system32\ncxml.dll
C:\WINDOWS\SYSTEM32\WBEM\BVGCMD02.DLL
C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL
C:\WINDOWS\system32\drivers\amdk5.sys
C:\WINDOWS\System32\Drivers\HTTP.sys
C:\WINDOWS\System32\DRIVERS\jscont22.sys
C:\WINDOWS\system32\drivers\LanPort.sys
C:\WINDOWS\system32\drivers\mffalmj.sys
C:\WINDOWS\system32\drivers\nwlnksipx.sys
C:\WINDOWS\system32\drivers\uphkfla.sys
C:\WINDOWS\system32\drivers\wspipe.sys
C:\WINDOWS\system32\484cntos.dll
C:\PROGRA~1\bnxa\frbe.dll

6、修复文件关联。
7、用LSPFix修复Winsock 。





1
查看完整版本: 这论坛怎么了?