瑞星卡卡安全论坛
yangin - 2007-4-1 7:33:00
C:\CONFIG.EXE 在进程里把这个结束就不发出咚声了 一重起就又出现了 怎么才能彻底的吧这个东西删除啊 !大哥门帮帮我啊
水树雨下 - 2007-4-1 7:38:00
手动删除,无法解决就扫日志上来
yangin - 2007-4-1 8:17:00
怎么扫日志啊 我不会呢 帮帮我呀
yangin - 2007-4-1 8:25:00
手动删了 重起了还是在啊
yangin - 2007-4-1 8:39:00
各位高手:
非常感谢留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2001-04-01 08:29:18
诊断平台: Microsoft Windows XP Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build: 62900.2180
100 - Process: smss.exe - C:\WINDOWS\system32\smss.exe
100 - Process: csrss.exe - C:\WINDOWS\system32\csrss.exe
100 - Process: winlogon.exe - C:\WINDOWS\system32\winlogon.exe
100 - Process: services.exe - C:\WINDOWS\system32\services.exe
100 - Process: lsass.exe - C:\WINDOWS\system32\lsass.exe
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost.exe
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost.exe
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost.exe
100 - Process: EvtEng.exe - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
100 - Process: S24EvMon.exe - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost.exe
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost.exe
100 - Process: spoolsv.exe - C:\WINDOWS\system32\spoolsv.exe
100 - Process: explorer.exe - C:\WINDOWS\explorer.exe
100 - Process: HControl.exe - C:\WINDOWS\ATK0100\HControl.exe
100 - Process: PDVDServ.exe - C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
100 - Process: rundll32.exe - C:\WINDOWS\system32\rundll32.exe
100 - Process: SynTPEnh.exe - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
100 - Process: wcourier.exe - C:\Program Files\Wireless Console 2\wcourier.exe
100 - Process: ZCfgSvc.exe - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
100 - Process: DMedia.exe - C:\Program Files\ASUS\ATK Media\DMedia.exe
100 - Process: ACMON.exe - C:\Program Files\ASUS\Splendid\ACMON.exe
100 - Process: hpwuSchd.exe - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe
100 - Process: hpcmpmgr.exe - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
100 - Process: hpotdd01.exe - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
100 - Process: realsched.exe - C:\Program Files\Common Files\Real\Update_OB\realsched.exe
100 - Process: 3.exe - C:\Program Files\WindowsUpdate\3.exe
100 - Process: norton.exe - C:\WINDOWS\norton.exe
100 - Process: ACEngSvr.exe - C:\WINDOWS\system32\ACEngSvr.exe
100 - Process: ctfmon.exe - C:\WINDOWS\system32\ctfmon.exe
100 - Process: IEXPLORE.EXE - C:\Program Files\Internet Explorer\IEXPLORE.EXE
100 - Process: MDM.EXE - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
100 - Process: nvsvc32.exe - C:\WINDOWS\system32\nvsvc32.exe
100 - Process: 5D851B22.exe - C:\WINDOWS\system32\5D851B22.exe
100 - Process: ATKOSD.exe - C:\WINDOWS\ATK0100\ATKOSD.exe
100 - Process: Generic.exe - C:\Program Files\Common Files\Teleca Shared\Generic.exe
100 - Process: epmworker.exe - C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
100 - Process: RegSrvc.exe - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
100 - Process: StarWindService.exe - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost.exe
100 - Process: wdfmgr.exe - C:\WINDOWS\system32\wdfmgr.exe
100 - Process: alg.exe - C:\WINDOWS\system32\alg.exe
100 - Process: ntvdm.exe - C:\WINDOWS\system32\ntvdm.exe
100 - Process: conime.exe - C:\WINDOWS\system32\conime.exe
100 - Process: VSClient.exe - F:\War3\VS竞技游戏平台\VSClient.exe
100 - Process: TTraveler.exe - C:\Program Files\Tencent\TT\TTraveler.exe
100 - Process: QQ.exe - C:\Program Files\Tencent\QQ\QQ.exe
100 - Process: TIMPlatform.exe - C:\Program Files\Tencent\QQ\TIMPlatform.exe
100 - Process: 360Safe.exe - C:\Program Files\360safe\360Safe.exe
100 - Process: safelive.exe - C:\Program Files\360safe\safelive.exe
R3 - URLSearchHook: (地址栏挂钩) - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} -
O2 - BHO: (Thunder Browser Helper) - {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (浏览器辅助对象(BHO)) - {0C7C23EF-A848-485B-873C-0ED954731014} -
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (浏览器辅助对象(BHO)) - {C64E4E3D-AAA0-4081-B6A7-22A40AFBFD35} -
O3 - Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (第三方IE工具栏) - {710EB7A1-45ED-11D0-924A-0020AFC7AC4D} -
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [POP] C:\Program Files\WindowsUpdate\3.exe
O4 - HKLM\..\Run: [Jiangmin KVFW] C:\Program Files\JiangMin\KVFW\KvfwMcl.exe
O4 - HKLM\..\Run: [norton] C:\WINDOWS\norton.exe
O4 - HKLM\..\Run: [winform] C:\WINDOWS\winform.exe
O4 - HKLM\..\RunOnce: [360Safe] Rundll32.exe C:\PROGRA~1\360safe\AntiAdwa.dll,KillAdware
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup folder: [腾讯QQ.lnk] C:\Documents and Settings\sue chen\「开始」菜单\程序\启动\腾讯QQ.lnk
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
O8 - Extra context menu item: Byna 搜索(&B) - res://C:\Program Files\BiGet\bigetcatch.dll/bigetsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: 启动迅雷5(HKLM)
O9 - Extra button: 浩方对战平台(HKLM)
O9 - Extra button: 信息检索(HKLM)
O9 - Extra button: 腾讯QQ(HKLM)
O9 - Extra button: Windows Messenger(HKLM)
O17 - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{64AF4F5A-5BE5-4581-A9F2-6E5C4C873B4B}: NameServer = 202.27.184.3,202.27.183.5
O18 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O18 - Protocol: CZipHandler Object - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: OFFICE 相关 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O23 - Service: 7F5DA206 - C:\WINDOWS\system32\7F5DA206.EXE
O23 - Service: EvtEng - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: hpdj - C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\hpdj.exe
O23 - Service: NVSvc - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: S24EventMonitor - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: StarWindService - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TomDemoService - C:\CONFIG.EXE
360安全卫士,为您的系统提供最全面的保护
最新下载:http://download.360safe.com
yangin - 2007-4-1 8:52:00
谁来看看啊
yangin - 2007-4-1 9:44:00
[CODE]
2001-04-01,09:27:43
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - ?????? - ????
???????:
???????(???????????????)
??????
???????(????????)
????
Winsock ???
Autorun.inf
HOSTS ??
????
???
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<333><C:\Syswm1i\svchost.exe> []
<4><C:\SysWsj7\svchost.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<HControl><C:\WINDOWS\ATK0100\HControl.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /install> []
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Publisher]
<RemoteControl><"C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"> [Cyberlink Corp.]
<NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Wireless Console 2><C:\Program Files\Wireless Console 2\wcourier.exe> []
<IntelZeroConfig><"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"> [Intel Corporation]
<ATKMEDIA><C:\Program Files\ASUS\ATK Media\DMEDIA.EXE> [ASUSTeK Computer INC.]
<Power_Gear><C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1> [N/A]
<ACMON><C:\Program Files\ASUS\Splendid\ACMON.exe> [ATK]
<ABLKSR><C:\WINDOWS\ABLKSR\ABLKSR.exe> [ASYSTeK Computer INC.]
<SMSERIAL><sm56hlpr.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<HPDJ Taskbar Utility><C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<HP Software Update><"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"> [Hewlett-Packard]
<HP Component Manager><"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"> [Hewlett-Packard Company]
<DeviceDiscovery><C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe> [Hewlett-Packard]
<Sony Ericsson PC Suite><"C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions> [Sony Ericsson Mobile Communications AB]
<Adobe Photo Downloader><"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"> [Adobe Systems Incorporated]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<POP><C:\Program Files\WindowsUpdate\3.exe> []
<Jiangmin KVFW><C:\Program Files\JiangMin\KVFW\KvfwMcl.exe> [N/A]
<norton><C:\WINDOWS\norton.exe> []
<winform><C:\WINDOWS\winform.exe> []
<nortonq><C:\WINDOWS\nortonq.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<upxdnd><C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\upxdnd.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<360Safe><Rundll32.exe C:\PROGRA~1\360safe\AntiAdwa.dll,KillAdware> [qihoo.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\Userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\ASUS_A~1.SCR> [ScreenTime Media]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ASUS Live Update><; C:\Program Files\ASUS\ASUS Live Update\ALU.exe> []
==================================
?????
[腾讯QQ]
<C:\Documents and Settings\sue chen\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQSafe.exe [SBM]><N>
==================================
??
[7F5DA206 / 7F5DA206][Stopped/Auto Start]
<C:\WINDOWS\system32\7F5DA206.EXE -service><Microsoft Corporation>
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Intel(R) PROSet/Wireless Event Log / EvtEng][Running/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[hpdj / hpdj][Stopped/Auto Start]
<C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\hpdj.exe -servicerunning=true -uninstall=hp deskjet 3500 series -product=><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Intel(R) PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Intel(R) PROSet/Wireless Service / S24EventMonitor][Running/Auto Start]
<C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation>
[StarWind iSCSI Service / StarWindService][Running/Auto Start]
<C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
[TomDemoService / TomDemoService][Stopped/Auto Start]
<C:\CONFIG.EXE><N/A>
yangin - 2007-4-1 9:46:00
==================================
????
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
<system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[AEGIS Protocol (IEEE 802.1x) v3.4.9.0 / AegisP][Running/Auto Start]
<system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
[bootdrv / bootdrv][Stopped/Boot Start]
<\SystemRoot\System32\Drivers\bootdrv.sys><N/A>
[ENTECH / ENTECH][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys><EnTech Taiwan>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[ipswuio / ipswuio][Stopped/Manual Start]
<System32\DRIVERS\ipswuio.sys><Windows (R) 2000 DDK provider>
[ATK0100 ACPI UTILITY / MTsensor][Running/Manual Start]
<system32\DRIVERS\ATKACPI.sys><>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[rimmptsk / rimmptsk][Running/Manual Start]
<system32\DRIVERS\rimmptsk.sys><REDC>
[rimsptsk / rimsptsk][Running/Manual Start]
<system32\DRIVERS\rimsptsk.sys><REDC>
[Ricoh xD-Picture Card Driver / rismxdp][Running/Manual Start]
<system32\DRIVERS\rixdptsk.sys><REDC>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtenicxp.sys><Realtek Semiconductor Corporation>
[WLAN 传输 / s24trans][Running/Auto Start]
<system32\DRIVERS\s24trans.sys><Intel Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SMSC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
<system32\DRIVERS\smcirda.sys><SMSC>
[smserial / smserial][Stopped/Manual Start]
<system32\DRIVERS\smserial.sys><Motorola Inc.>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tb / tb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\tb.sys><N/A>
[Vimicro USB PC Camera (VC0321) / usbvm321][Running/Manual Start]
<System32\Drivers\usbvm321.sys><Vimicro Corporation>
[vaxscsi / vaxscsi][Running/Manual Start]
<\SystemRoot\System32\Drivers\vaxscsi.sys><N/A>
[Intel(R) PRO/Wireless 3945ABG Adapter Driver / w39n51][Stopped/Manual Start]
<system32\DRIVERS\w39n51.sys><Intel? Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
==================================
??????
[Thunder Browser Helper]
{06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Live Sign-in Helper]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <F:\War3\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Thunder Browser Helper]
{06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Live Sign-in Helper]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[&Windows Live Search]
<res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm, N/A>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[Byna 搜索(&B)]
<res://C:\Program Files\BiGet\bigetcatch.dll/bigetsearch.html, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
<C:\Program Files\BitSpirit\bsurl.htm, N/A>
咕噜猪zzZ睡觉觉 - 2007-4-1 9:48:00
QQ先别上了
待会儿是个盗好的
yangin - 2007-4-1 9:49:00
==================================
???????
[PID: 736][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 788][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\7F5DA206.DLL] [Microsoft Corporation, ]
[PID: 860][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 872][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1028][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1108][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 356][C:\WINDOWS\ATK0100\HControl.exe] [, 1043, 2, 15, 58]
[C:\WINDOWS\ATK0100\CMSSC.dll] [N/A, ]
[C:\WINDOWS\ATK0100\inter_f2.dll] [ATK, 1043, 2, 15, 52]
[C:\WINDOWS\ATK0100\ATKWLIOC.DLL] [ACTIONTEC Electronics,Inc, 2.01.02]
[C:\WINDOWS\ATK0100\SiSPkt.dll] [Silicon Integrated Systems Corp., 1, 0, 0, 45]
[C:\Program Files\Intel\Wireless\Bin\MurocApi.dll] [Intel Corporation, 10, 1, 0, 37]
[C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll] [Intel Corporation, 10, 1, 0, 1]
[C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll] [Intel Corporation, 10, 1, 0, 2]
[C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL] [Intel Corporation, 10, 1, 0, 5]
[C:\Program Files\Intel\Wireless\Bin\IntStngs.dll] [, 10, 1, 0, 3]
[C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll] [N/A, ]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.2.0 21Oct05]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 392][C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe] [Cyberlink Corp., 6.00.1027]
[C:\Program Files\ASUSTeK\ASUSDVD\CLRCEngine2.dll] [CyberLink Corp., 3.2.2021 ]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 400][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8426]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 420][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 8.2.0 21Oct05]
[C:\WINDOWS\system32\SynCOM.dll] [Synaptics, Inc., 8.2.0 21Oct05]
[C:\WINDOWS\system32\SynTPAPI.dll] [Synaptics, Inc., 8.2.0 21Oct05]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 436][C:\Program Files\Wireless Console 2\wcourier.exe] [, 2, 0, 2, 0]
[C:\Program Files\Wireless Console 2\MSIMG32.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Wireless Console 2\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 440][C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe] [Intel Corporation, 10, 1, 0, 42]
[C:\Program Files\Intel\Wireless\bin\PfMgrApi.dll] [Intel Corporation, 10, 1, 0, 46]
[C:\Program Files\Intel\Wireless\bin\TraceAPI.DLL] [Intel Corporation, 10, 1, 0, 5]
[C:\Program Files\Intel\Wireless\bin\PsRegApi.dll] [Intel Corporation, 10, 1, 0, 2]
[C:\Program Files\Intel\Wireless\bin\DbEngine.dll] [Intel Corporation, 10, 1, 0, 13]
[C:\Program Files\Intel\Wireless\bin\LIBEAY32.dll] [N/A, ]
[C:\Program Files\Intel\Wireless\bin\IntStngs.dll] [, 10, 1, 0, 3]
[C:\Program Files\Intel\Wireless\bin\MurocApi.dll] [Intel Corporation, 10, 1, 0, 37]
[C:\Program Files\Intel\Wireless\bin\S24MUDLL.dll] [Intel Corporation, 10, 1, 0, 1]
[C:\Program Files\Intel\Wireless\Bin\ZcSvcCHS.dll] [Intel Corporation, 10, 1, 0, 42]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 464][C:\Program Files\ASUS\ATK Media\DMEDIA.EXE] [ASUSTeK Computer INC., 1, 11, 0, 0]
[C:\Program Files\ASUS\ATK Media\ATKMETHOD.dll] [ASUSTeK Computer Inc., 1, 11, 0, 0]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 528][C:\Program Files\ASUS\Splendid\ACMON.exe] [ATK, 1, 0, 4, 221]
[C:\Program Files\ASUS\Splendid\GLCDdll.dll] [, 1, 0, 0, 729]
[C:\Program Files\ASUS\Splendid\Chameleon.dll] [ASUSTeK, 1, 0, 0, 3]
[C:\Program Files\ASUS\Splendid\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 568][C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe] [Hewlett-Packard, 1, 0, 0, 2]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 576][C:\Program Files\HP\hpcoretech\hpcmpmgr.exe] [Hewlett-Packard Company, 1.7.1.0]
[C:\Program Files\HP\hpcoretech\HPVCR70.dll] [Microsoft Corporation, 7.00.9466.0]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9841.0]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 588][C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe] [Hewlett-Packard, 1, 0, 0, 1]
[C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodvd08.dll] [Hewlett-Packard, 2, 0, 2, 2]
[C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxm08.dll] [Hewlett-Packard Co., 4.2.0.127]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 656][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3760]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 724][C:\Program Files\WindowsUpdate\3.exe] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 1012][C:\WINDOWS\norton.exe] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\norton.dll] [N/A, ]
[PID: 1160][C:\WINDOWS\system32\ACEngSvr.exe] [ASUSTeK, 1, 0, 0, 4]
[C:\WINDOWS\system32\icm32.dll] [Microsoft Corporation, 5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)]
[PID: 1376][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 1400][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
yangin - 2007-4-1 9:49:00
[C:\Program Files\Windows Live Toolbar\msntb.dll] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\zh-hk\mtbres.dll.mui] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\mtbres.dll] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\Tem.dll] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\zh-hk\CMRes.dll.mui] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\CMRes.dll] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\zh-hk\msn_slrs.DLL.mui] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\msn_slrs.DLL] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll] [Microsoft Corporation, 4.000.249.1]
[C:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll] [Microsoft Corporation, 4.000.249.1]
[C:\Program Files\Windows Live Toolbar\stmain.dll] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\cm.dll] [Microsoft Corporation, 03.00.0000.1615]
[C:\Program Files\Windows Live Toolbar\msn_slps.dll] [Microsoft Corporation, 03.00.0000.1615]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 2376][C:\WINDOWS\system32\5D851B22.exe] [N/A, ]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 2384][C:\WINDOWS\ATK0100\ATKOSD.exe] [, 1043, 2, 15, 57]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 2432][C:\Program Files\Common Files\Teleca Shared\Generic.exe] [Teleca Software Solutions, 1, 0, 3, 2]
[C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll] [Teleca/Popwire AB, 1, 0, 2, 3]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll] [N/A, ]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9841.0]
[C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt.dll] [Teleca Software Solutions, 1, 0, 1, 1]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8426]
[C:\Program Files\Sony Ericsson\Mobile2\Device Manager\SpecificMPM.dll] [SonyEricsson, 1, 0, 2, 1]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll] [N/A, ]
[C:\Program Files\Common Files\Teleca Shared\SpecificUSB.dll] [Popwire AB, 1, 2, 1, 1]
[C:\Program Files\Common Files\Teleca Shared\tlib_log.dll] [Popwire AB, 1, 0, 3, 3]
[C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 2528][C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe] [Sony Ericsson Mobile Communications AB, 1, 2, 0,1186]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ShowMfcDialog.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,118]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\Capires0804.DLL] [Popwire AB, 1, 0, 0,2013]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll] [N/A, ]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cabmain.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,1222]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9841.0]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msmeirsock_object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,941]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ms98irsock_object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,986]
[C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msirsock_object.dll] [Sony Ericsson Mobile Communications AB, 1, 0, 0,998]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 3936][C:\WINDOWS\system32\ntvdm.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3952][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 3096][F:\War3\VS竞技游戏平台\VSClient.exe] [广州唯思软件有限公司, 1, 1, 0, 1]
[F:\War3\VS竞技游戏平台\CSDT.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\WYClientDataAPI.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\VSFace.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\VSIPC.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[F:\War3\VS竞技游戏平台\dbghelp.dll] [Microsoft Corporation, 5.00.2195.6613]
[F:\War3\VS竞技游戏平台\WARDT.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\WEDT.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\scscdt.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\MapSource.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\LiveCtrl.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\SCLiveDT.dll] [N/A, ]
[F:\War3\VS竞技游戏平台\VSRes.dll] [N/A, ]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8426]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
yangin - 2007-4-1 9:50:00
[PID: 2064][C:\Program Files\Tencent\TT\TTraveler.exe] [腾讯公司, 3.2.200.275]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 3]
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8426]
[C:\WINDOWS\system32\PNCRT.dll] [Real Networks, Inc, 6.0.0.0]
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] [RealNetworks, Inc., 6.0.9.4317]
[C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL] [Microsoft Corporation, 1.0.1038.0]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[PID: 3784][C:\Program Files\Tencent\QQ\QQ.EXE] [TENCENT, 0, 0, 0, 0]
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [Tencent, 7, 0, 101, 80]
[C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\Program Files\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[C:\Program Files\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[C:\Program Files\Tencent\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[C:\Program Files\Tencent\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[C:\Program Files\Tencent\QQ\LoginCtrlRes.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\GroupLive.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[C:\Program Files\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Tencent\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\LongConnection.dll] [tencent, 5, 0, 200, 160]
[C:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\Program Files\Tencent\QQ\QQPet.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8426]
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 280]
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, ]
[C:\Program Files\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 6, 60]
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, ]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Tencent\QQ\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\Program Files\Tencent\QQ\GroupConnection.dll] [Tencent, 0, 3, 3, 5]
[C:\Program Files\Tencent\QQ\QQZip.dll] [tencent, 0, 3, 2, 4]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[PID: 1428][C:\Program Files\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 2056][C:\Program Files\360safe\safelive.exe] [qihoo.com, 1, 0, 0, 1001]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\Program Files\360safe\live.dll] [Qihoo.Com, 1, 0, 0, 1002]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 2260][C:\WINDOWS\nortonq.exe] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\nortonq.dll] [N/A, ]
[PID: 412][c:\Syswm1i\svchost.exe] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 3868][c:\SysWsj7\svchost.exe] [N/A, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[PID: 3260][C:\Program Files\Tencent\QQ\QZone\Qzone.exe] [腾讯公司, 1, 7, 101, 14]
[C:\Program Files\Tencent\QQ\QZone\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 3488][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8426]
[C:\WINDOWS\system32\7F5DA206.DLL] [Microsoft Corporation, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[PID: 3604][C:\WINDOWS\system32\5D851B22.exe] [N/A, ]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 1416][C:\Documents and Settings\sue chen\桌面\新建文件夹 (2)\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\nview.dll] [, ]
[c:\SysWsj7\Ghook.dll] [N/A, ]
[c:\Syswm1i\Ghook.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8426]
==================================
????
.TXT Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [C:\WINDOWS\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock ???
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS ??
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
????
N/A
==================================
[/CODE]
吾虾米 - 2007-4-1 9:59:00
C:\CONFIG.EXE 不知道是啥东东,一开机就把瑞星小绿伞给关了,我在手动删除CONFIG.EXE后,没再作怪了。
yangin - 2007-4-1 10:01:00
可是重起后还是在的哦
赤日炎炎 - 2007-4-1 10:01:00
机器染了一大堆毒,不是单一的CONFIG.EXE。要删除C:\CONFIG.EXE首先要先结束进程C:\CONFIG.EXE,再将[TomDemoService / TomDemoService][Stopped/Auto Start]干掉,并将注册表里所有CONFIG.EXE键值干掉。
另外启动项
<333><C:\Syswm1i\svchost.exe> []
<4><C:\SysWsj7\svchost.exe> []
<POP><C:\Program Files\WindowsUpdate\3.exe> []
<Jiangmin KVFW><C:\Program Files\JiangMin\KVFW\KvfwMcl.exe> [N/A]
<norton><C:\WINDOWS\norton.exe> []
<winform><C:\WINDOWS\winform.exe> []
<nortonq><C:\WINDOWS\nortonq.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<upxdnd><C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\upxdnd.exe> []
服务项里
[7F5DA206 / 7F5DA206][Stopped/Auto Start]
<C:\WINDOWS\system32\7F5DA206.EXE -service><Microsoft Corporation>
[hpdj / hpdj][Stopped/Auto Start]
<C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\hpdj.exe -servicerunning=true -uninstall=hp deskjet 3500 series -product=><N/A>
也十之八九是病毒,按干掉[TomDemoService / TomDemoService][Stopped/Auto Start]的方法干掉
没仔细看,还有其他病毒
jmbt - 2007-4-1 10:09:00
天哪,这么多病毒呀
spiritfire - 2007-4-1 10:11:00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<333><C:\Syswm1i\svchost.exe> []
<4><C:\SysWsj7\svchost.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<POP><C:\Program Files\WindowsUpdate\3.exe> []
<norton><C:\WINDOWS\norton.exe> []
<winform><C:\WINDOWS\winform.exe> []
<nortonq><C:\WINDOWS\nortonq.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<upxdnd><C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\upxdnd.exe> []
[7F5DA206 / 7F5DA206][Stopped/Auto Start]
<C:\WINDOWS\system32\7F5DA206.EXE -service><Microsoft Corporation>
[TomDemoService / TomDemoService][Stopped/Auto Start]
<C:\CONFIG.EXE><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
用SREng删除以上启动项目及服务,安全模式下清空C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp,并删除如下
文件:
C:\WINDOWS\system32\DRIVERS\npf.sys
C:\CONFIG.EXE
C:\WINDOWS\system32\7F5DA206.EXE
C:\Program Files\WindowsUpdate\3.exe
C:\WINDOWS\norton.exe
C:\WINDOWS\winform.exe
C:\WINDOWS\nortonq.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\cmdbcs.exe
C:\Syswm1i\svchost.exe
C:\SysWsj7\svchost.exe
c:\Syswm1i\Ghook.dll
c:\SysWsj7\Ghook.dll
C:\WINDOWS\system32\norton.dll
C:\WINDOWS\system32\5D851B22.exe
C:\WINDOWS\system32\nview.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\nortonq.exe
C:\WINDOWS\system32\nortonq.dll
C:\WINDOWS\system32\mppds.dll
[C:\WINDOWS\system32\winform.dll
[C:\WINDOWS\system32\msccrt.dll
[C:\WINDOWS\system32\cmdbcs.dll
置顶的工具帖子中下载,killbox,运行后,填入下面文件路径,勾选“替换后重启”处理!
C:\WINDOWS\system32\7F5DA206.DLL
卸载掉QQ,删除整个tencent文件夹,重新安装QQ,兔子完整清理系统!
PS:最好用农夫的威金专杀断网杀一遍!
spiritfire - 2007-4-1 10:14:00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<333><C:\Syswm1i\svchost.exe> []
<4><C:\SysWsj7\svchost.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<POP><C:\Program Files\WindowsUpdate\3.exe> []
<norton><C:\WINDOWS\norton.exe> []
<winform><C:\WINDOWS\winform.exe> []
<nortonq><C:\WINDOWS\nortonq.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<upxdnd><C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\upxdnd.exe> []
[7F5DA206 / 7F5DA206][Stopped/Auto Start]
<C:\WINDOWS\system32\7F5DA206.EXE -service><Microsoft Corporation>
[TomDemoService / TomDemoService][Stopped/Auto Start]
<C:\CONFIG.EXE><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
用SREng删除以上启动项目及服务,安全模式下清空C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp,并删除如下
文件:
C:\WINDOWS\system32\DRIVERS\npf.sys
C:\CONFIG.EXE
C:\WINDOWS\system32\7F5DA206.EXE
C:\Program Files\WindowsUpdate\3.exe
C:\WINDOWS\norton.exe
C:\WINDOWS\winform.exe
C:\WINDOWS\nortonq.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\cmdbcs.exe
C:\Syswm1i\svchost.exe
C:\SysWsj7\svchost.exe
c:\Syswm1i\Ghook.dll
c:\SysWsj7\Ghook.dll
C:\WINDOWS\system32\norton.dll
C:\WINDOWS\system32\5D851B22.exe
C:\WINDOWS\system32\nview.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\nortonq.exe
C:\WINDOWS\system32\nortonq.dll
C:\WINDOWS\system32\mppds.dll
[C:\WINDOWS\system32\winform.dll
[C:\WINDOWS\system32\msccrt.dll
[C:\WINDOWS\system32\cmdbcs.dll
置顶的工具帖子中下载,killbox,运行后,填入下面文件路径,勾选“替换后重启”处理!
C:\WINDOWS\system32\7F5DA206.DLL
卸载掉QQ,删除整个tencent文件夹,重新安装QQ,兔子完整清理系统!
PS:最好用农夫的威金专杀断网杀一遍!
newcenturymoon - 2007-4-1 10:17:00
C:\CONFIG.EXE是最新的蠕虫病毒
竹林ぁ风 - 2007-4-1 10:27:00
| 引用: |
【spiritfire的贴子】[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] <333><C:\Syswm1i\svchost.exe> [] <4><C:\SysWsj7\svchost.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<POP><C:\Program Files\WindowsUpdate\3.exe> [] <norton><C:\WINDOWS\norton.exe> [] <winform><C:\WINDOWS\winform.exe> [] <nortonq><C:\WINDOWS\nortonq.exe> [] <mppds><C:\WINDOWS\mppds.exe> [] <msccrt><C:\WINDOWS\msccrt.exe> [] <cmdbcs><C:\WINDOWS\cmdbcs.exe> [] <upxdnd><C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp\upxdnd.exe> []
[7F5DA206 / 7F5DA206][Stopped/Auto Start] <C:\WINDOWS\system32\7F5DA206.EXE -service><Microsoft Corporation>
[TomDemoService / TomDemoService][Stopped/Auto Start] <C:\CONFIG.EXE><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start] <system32\DRIVERS\npf.sys><CACE Technologies>
用SREng删除以上启动项目及服务,安全模式下清空C:\DOCUME~1\SUECHE~1\LOCALS~1\Temp,并删除如下
文件:
C:\WINDOWS\system32\DRIVERS\npf.sys C:\CONFIG.EXE C:\WINDOWS\system32\7F5DA206.EXE C:\Program Files\WindowsUpdate\3.exe C:\WINDOWS\norton.exe C:\WINDOWS\winform.exe C:\WINDOWS\nortonq.exe C:\WINDOWS\mppds.exe C:\WINDOWS\msccrt.exe C:\WINDOWS\cmdbcs.exe C:\Syswm1i\svchost.exe C:\SysWsj7\svchost.exe c:\Syswm1i\Ghook.dll c:\SysWsj7\Ghook.dll C:\WINDOWS\system32\norton.dll C:\WINDOWS\system32\5D851B22.exe C:\WINDOWS\system32\nview.dll C:\WINDOWS\system32\cmdbcs.dll C:\WINDOWS\nortonq.exe C:\WINDOWS\system32\nortonq.dll C:\WINDOWS\system32\mppds.dll [C:\WINDOWS\system32\winform.dll [C:\WINDOWS\system32\msccrt.dll [C:\WINDOWS\system32\cmdbcs.dll
置顶的工具帖子中下载,killbox,运行后,填入下面文件路径,勾选“替换后重启”处理! C:\WINDOWS\system32\7F5DA206.DLL
卸载掉QQ,删除整个tencent文件夹,重新安装QQ,兔子完整清理系统!
PS:最好用农夫的威金专杀断网杀一遍! ……………… |

好多,我都看不下去~!~!楼上的真厉害~!
spiritfire - 2007-4-1 12:08:00
| 引用: |
【newcenturymoon的贴子】C:\CONFIG.EXE是最新的蠕虫病毒 ……………… |
有专杀么?
newcenturymoon - 2007-4-1 12:09:00
还没有 马上瑞星会升级查杀
1
© 2000 - 2026 Rising Corp. Ltd.