瑞星卡卡安全论坛
你好aaaaaaa - 2007-8-30 18:02:00
救命~史上非常厉害的病毒~弄得我只能上安全模式~正常模式和网都上不到,电脑N慢
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\windows\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<Google Desktop Search><"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HP Software Update><C:\Program Files\HP\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Development Company, L.P.]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<SMSTray><C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe> [SAMSUNG ELECTRONICS]
<MAAgent><C:\Program Files\MarkAny\ContentSafer\MAAgent.exe> [(?)????]
<Internat><Internet.Exe> [N/A]
<RunShadowTip><C:\windows\system32\shadow\ShadowTip.exe> [PowerShadow]
<miniqqlive><"F:\QQGame\527911508\MiniQQLive.exe"> [Tencent]
<SmCtrlDrv><D;]xjoepxt]tztufn43]Svoemm43/fyf!D;]xjoepxt]tztufn43]deoqsi/emm!Tubsu> [N/A]
<IdnSvr><C:\Program Files\OCINS\idnsvr.exe> [中国互联网信息中心(CNNIC)]
<avpjz><C:\Program Files\NetMeeting\avpjz.exe> [N/A]
<cmdbcs><C:\windows\cmdbcs.exe> [N/A]
<AVPSrv><C:\windows\AVPSrv.exe> [N/A]
<WebThunder><"F:\BitSpirit\WebThunder.exe" /autostart> [深圳市迅雷网络技术有限公司]
<avpms><C:\Program Files\NetMeeting\avpms.exe> [N/A]
<AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [Yahoo! China]
<yassistse><c:\progra~1\yahoo!\assistant\yassistse.exe> [Yahoo! China]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [N/A]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<a8mw><%systemroot%\system32\Rundll32.exe %systemroot%\system32\a8mw.dll,DllUnregisterServer> [N/A]
<pcibc><%systemroot%\system32\regsvr32.exe /s %systemroot%\system32\wuxztt.dll> [N/A]
<hvxtxh74><%systemroot%\system32\Rundll32.exe %systemroot%\system32\hvxtxh74.dll DllUnregisterServer> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<Userinit><rundll32.exe C:\windows\system32\winsys16_070830.dll start> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe webhelp.exe> [N/A]
<Userinit><C:\windows\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><jhbpri.dll> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Corporation]
<{88485281-8b4b-4f8d-9ede-82e29a064277}><C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL> [MarkAny Cooperation.]
<{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys> [N/A]
<{5182C1EB-375C-573D-1F5E-234552345215}><C:\windows\system32\wlhpri.dll> [N/A]
<{6562452F-FA36-BA4F-892A-FF5FBBAC5316}><C:\windows\system32\myfpri.dll> [N/A]
<{E1351752-5628-1547-FFAB-BADC13512AFE}><C:\windows\system32\ztaman.dll> [N/A]
<{42311A42-AC1B-158F-FD32-5674345F23A4}><C:\windows\system32\dhdpri.dll> [N/A]
<{A13AF41A-21B1-131B-1BFC-D2A90DF4A2BA}><C:\windows\system32\xyipri.dll> [N/A]
<{9A65498A-7653-9801-1647-987114AB7F49}><C:\windows\system32\zxipri.dll> [N/A]
<{C5E87A05-F463-4841-B19E-DD3EC3862368}><C:\Program Files\Internet Explorer\IEXPLORE32.Sys> [N/A]
<{EE12D60D-AD9A-4095-B839-3BE6862679FD}><C:\Program Files\Internet Explorer\IEXPLORE32.Dat> [N/A]
<{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}><C:\Program Files\Internet Explorer\IEXPLORE32.win> [N/A]
<{352D2432-37A2-324F-2A54-21BF5CF2F1A3}><C:\windows\system32\jhbpri.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Corporation]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><C:\windows\system32\klogon.dll> [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\system32\ssmypics.scr> [(Verified)Microsoft Corporation]
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; TencentTraveler ; (R1 1.5))
你好aaaaaaa - 2007-8-30 18:02:00
启动文件夹
[HP Digital Imaging Monitor]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HP Digital Imaging Monitor.lnk --> C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [Hewlett-Packard Development Company, L.P.]><N>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> F:\g\QQ.exe [TENCENT]><N>
[QQ游戏启动加速程序]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> F:\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
==================================
服务
[219829DA / 219829DA]
<C:\windows\system32\D401AB94.EXE -g><Microsoft Corporation>
[卡巴斯基反病毒6.0个人版 / AVP]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[FirebirdGuardianDefaultInstance / FirebirdGuardianDefaultInstance]
<C:\PROGRA~1\广东省~1\FireBird\bin\fbguard.exe -s><The Firebird Project>
[FirebirdServerDefaultInstance / FirebirdServerDefaultInstance]
<C:\PROGRA~1\广东省~1\FireBird\bin\fbserver.exe -s -g><The Firebird Project>
[Human Interface Device Access / HidServ]
<C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Shadow System Service / ShadowSystemService]
<C:\windows\system32\shadow\ShadowService.exe><N/A>
[svchost / svchost]
<C:\windows\system32\dllcache\svchost.exe -g><Microsoft Corporation>
[Windows Media Server / Windows Media Server]
<C:\windows\services.exe><N/A>
==================================
驱动程序
[8kx6ajgsw / 8kx6ajgsw]
<\??\C:\windows\system32\drivers\8kx6ajgsw.sys><N/A>
[abp480n5 / abp480n5]
<C:\windows\SYSTEM32\DRIVERS\abp480n5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
<system32\drivers\ac97intc.sys><Intel Corporation>
[acpidisk / acpidisk]
<\??\C:\windows\system32\drivers\acpidisk.sys><N/A>
[aic78u2 / aic78u2]
<C:\windows\SYSTEM32\DRIVERS\aic78u2.SYS><Microsoft Corporation>
[aic78xx / aic78xx]
<C:\windows\SYSTEM32\DRIVERS\aic78xx.SYS><Microsoft Corporation>
[AliIde / AliIde]
<C:\windows\SYSTEM32\DRIVERS\AliIde.SYS><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8]
<System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[USB 2.0 Compliance JPEG Video Camera / CAM1690]
<System32\Drivers\cam1690.sys><>
[cd20xrnt / cd20xrnt]
<C:\windows\SYSTEM32\DRIVERS\cd20xrnt.SYS><Microsoft Corporation>
[CmdIde / CmdIde]
<C:\windows\SYSTEM32\DRIVERS\CmdIde.SYS><CMD Technology, Inc.>
[cnprov / cnprov]
<\SystemRoot\system32\drivers\cnprov.sys><中国互联网络信息中心(CNNIC)>
[Desekeov / Desekeov]
<C:\windows\SYSTEM32\DRIVERS\Desekeov.SYS><N/A>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[hvxtxh7 / hvxtxh74]
<\SystemRoot\System32\DRIVERS\hvxtxh74.sys><N/A>
[ialm / ialm]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[idnaux / idnaux]
<system32\drivers\idnaux.sys><中国互联网络信息中心(CNNIC)>
[kl1 / kl1]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif]
<\??\C:\windows\system32\drivers\klif.sys><Kaspersky Lab>
[kmsinput / kmsinput]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[kxagilks / kxagilks]
<\SystemRoot\System32\DRIVERS\kxagilks.sys><Yahoo! China Corporation>
[mraid35x / mraid35x]
<C:\windows\SYSTEM32\DRIVERS\mraid35x.SYS><American Megatrends Inc.>
[npkcrypt / npkcrypt]
<\??\F:\g\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp]
<\??\F:\g\npkycryp.sys><N/A>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[pcib / pcibc]
<\SystemRoot\System32\DRIVERS\pcibc.sys><N/A>
[Pevezer / Pevezera]
<C:\windows\SYSTEM32\DRIVERS\Pevezera.SYS><N/A>
[Proc / Proc]
<C:\windows\SYSTEM32\DRIVERS\Proc.SYS><N/A>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[QKeyServiceDisplay / QKeyService]
<\SystemRoot\system32\KeyCrypt.sys><Tencent Technology (Shenzhen) Company Limited>
[ql1080 / ql1080]
<C:\windows\SYSTEM32\DRIVERS\ql1080.SYS><QLogic Corporation>
[Ql10wnt / Ql10wnt]
<C:\windows\SYSTEM32\DRIVERS\Ql10wnt.SYS><Microsoft Corporation>
[ql12160 / ql12160]
<C:\windows\SYSTEM32\DRIVERS\ql12160.SYS><QLogic Corporation>
[ql1280 / ql1280]
<C:\windows\SYSTEM32\DRIVERS\ql1280.SYS><QLogic Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[snpshot / snpshot]
<C:\windows\SYSTEM32\DRIVERS\snpshot.SYS><PowerShadow>
[Sparrow / Sparrow]
<C:\windows\SYSTEM32\DRIVERS\Sparrow.SYS><Adaptec, Inc.>
[symc810 / symc810]
<C:\windows\SYSTEM32\DRIVERS\symc810.SYS><Symbios Logic Inc.>
[symc8xx / symc8xx]
<C:\windows\SYSTEM32\DRIVERS\symc8xx.SYS><LSI Logic>
[sym_hi / sym_hi]
<C:\windows\SYSTEM32\DRIVERS\sym_hi.SYS><LSI Logic>
[sym_u3 / sym_u3]
<C:\windows\SYSTEM32\DRIVERS\sym_u3.SYS><LSI Logic>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TesSafe / TesSafe]
<\??\C:\windows\system32\TesSafe.sys><TENCENT>
[TosIde / TosIde]
<C:\windows\SYSTEM32\DRIVERS\TosIde.SYS><Microsoft Corporation>
[TSP / TSP]
<\??\C:\windows\system32\drivers\klif.sys><Kaspersky Lab>
[u39u / u39u8]
<\SystemRoot\System32\DRIVERS\u39u8.sys><N/A>
[ultra / ultra]
<C:\windows\SYSTEM32\DRIVERS\ultra.SYS><Promise Technology, Inc.>
[ViaIde / ViaIde]
<C:\windows\SYSTEM32\DRIVERS\ViaIde.SYS><Microsoft Corporation>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio]
<system32\drivers\vinyl97.sys><VIA Technologies, Inc.>
[World Standard Teletext Codec / WSTCODEC]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
你好aaaaaaa - 2007-8-30 18:03:00
浏览器加载项
[DLMgr Class]
{00000000-0000-0000-0000-000000000000} <D:\Program Files\Dianlei\Plugins\DLManager.dll, 电雷超级下载>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <F:\BitSpirit\WebThunderBHO_Now.dll, Thunder Networking Technologies,LTD>
[sosHlpr Class]
{00C104F7-0F5C-470C-ABCF-A5B2E70752F1} <C:\windows\system32\wuxztt.dll, Microsoft Corporation>
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, N/A>
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, yahoo! china>
[腾讯QQ]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\WINDOWS\QQIEHelper.dll, N/A>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[IEAux Class]
{7605CC7C-00FD-4A5F-BAFD-828342DE6279} <C:\PROGRA~1\OCINS\ieaux.dll, 中国互联网络信息中心(CNNIC)>
[assist]
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo! China>
[Web反病毒统计]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew, N/A>
[启动WEB迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[中文上网]
{B012491E-8FA4-4851-AA9B-22E33784FBAD} <C:\Program Files\OCINS\config.exe, 中国互联网络信息中心(CNNIC)>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <F:\g\QQ.EXE, TENCENT>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, yahoo! china>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[PhotoDraw Class]
{2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <C:\windows\system32\QQPhotoDraw.dll, TENCENT>
[EditCtrl Class]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\windows\system32\aliedit\aliedit.dll, >
[HnCtrl Class]
{8DD9C2E0-50B6-46BC-BB00-2D252282BFCA} <C:\PROGRA~1\hnnn\HNACTI~1.DLL, >
[VqqSpeedDlProxy Class]
{9ADACAA6-533E-4383-AFA7-F0A66650B6D8} <C:\windows\vqqsdl10.dll, Tencent Technology (Shenzhen) Company Limited>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\windows\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[PasswordEditCtrl Class]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <E:\rar\QQ\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[BoBoControl Class]
{EC0978ED-24E3-403C-AB7A-060E388553E6} <C:\WINDOWS\Downloaded Program Files\BoBo_ActiveX_V3.ocx, 广州易播信息科技有限公司>
[DLMgr Class]
{00000000-0000-0000-0000-000000000000} <D:\Program Files\Dianlei\Plugins\DLManager.dll, 电雷超级下载>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <F:\BitSpirit\WebThunderBHO_Now.dll, Thunder Networking Technologies,LTD>
[sosHlpr Class]
{00C104F7-0F5C-470C-ABCF-A5B2E70752F1} <C:\windows\system32\wuxztt.dll, Microsoft Corporation>
[WebThunder Class]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, N/A>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Yahoo!Photo]
{33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, yahoo! china>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, yahoo! china>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[腾讯QQ]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\WINDOWS\QQIEHelper.dll, N/A>
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Microsoft 外壳 UI 帮助程序]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[IEAux Class]
{7605CC7C-00FD-4A5F-BAFD-828342DE6279} <C:\PROGRA~1\OCINS\ieaux.dll, 中国互联网络信息中心(CNNIC)>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\windows\system32\Mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\windows\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[assist]
{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo! China>
[&访问通用网址]
<C:\Program Files\OCINS\cnrbtn.html, N/A>
[上传到QQ网络硬盘]
<F:\g\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<F:\BitSpirit\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<F:\BitSpirit\GetAllUrl.htm, N/A>
[使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<F:\g\AddPanel.htm, N/A>
[添加到QQ表情]
<F:\g\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
<F:\g\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
<F:\BitSpirit\bsurl.htm, N/A>
[百度-搜索MP3]
<res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUMP3.HTM, N/A>
[百度-搜索图片]
<, N/A>
[百度-搜索新闻]
<res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUNEWS.HTM, N/A>
[百度-搜索歌词]
<res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDULYRIC.HTM, N/A>
[百度-搜索网页]
<res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUSEARCH.HTM, N/A>
[百度-搜索贴吧]
<res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUPOST.HTM, N/A>
[百度-词典搜索]
<res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDU_DIC.HTM, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/203, N/A>
你好aaaaaaa - 2007-8-30 18:03:00
正在运行的进程
[PID: 168][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 220][\??\C:\windows\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 244][\??\C:\windows\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[C:\windows\system32\klogon.dll] [Kaspersky Lab, 6.0.2.621]
[PID: 292][C:\windows\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[PID: 304][C:\windows\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[PID: 456][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[PID: 508][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll] [N/A, N/A]
[PID: 580][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[PID: 832][C:\windows\Explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\zxipri.dll] [N/A, N/A]
[C:\windows\KB918127.log] [N/A, N/A]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll] [N/A, N/A]
[PID: 832][C:\windows\netdde32.exe] [N/A, N/A]
[PID: 832][C:\windows\system32\netdde32.exe] [N/A, N/A]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, N/A]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[C:\windows\system32\myfpri.dll] [N/A, N/A]
[C:\windows\system32\ztaman.dll] [N/A, N/A]
[C:\windows\system32\dhdpri.dll] [N/A, N/A]
[C:\windows\system32\xyipri.dll] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE32.Sys] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE32.Dat] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE32.win] [N/A, N/A]
[C:\windows\system32\jhbpri.dll] [N/A, N/A]
[C:\windows\system32\webshow.dll] [, 1.1.1.333]
[C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL] [MarkAny Cooperation., 1, 4, 0, 1]
[PID: 1112][C:\windows\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, N/A]
[C:\windows\system32\zxipri.dll] [N/A, N/A]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[C:\windows\system32\jhbpri.dll] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE32.Dat] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE32.Sys] [N/A, N/A]
[C:\windows\system32\xyipri.dll] [N/A, N/A]
[C:\windows\system32\dhdpri.dll] [N/A, N/A]
[C:\windows\system32\ztaman.dll] [N/A, N/A]
[C:\windows\system32\myfpri.dll] [N/A, N/A]
[PID: 1256][D:\11111111111\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, N/A]
[C:\windows\system32\wlhpri.dll] [N/A, N/A]
[C:\windows\system32\zxipri.dll] [N/A, N/A]
[C:\windows\system32\jhbpri.dll] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE32.Dat] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE32.Sys] [N/A, N/A]
[C:\windows\system32\xyipri.dll] [N/A, N/A]
[C:\windows\system32\dhdpri.dll] [N/A, N/A]
[C:\windows\system32\ztaman.dll] [N/A, N/A]
[C:\windows\system32\myfpri.dll] [N/A, N/A]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\windows\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
Google Desktop over [MSAFD Tcpip [TCP/IP]]
C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll(N/A, N/A)
Google Desktop over [MSAFD Tcpip [UDP/IP]]
C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll(N/A, N/A)
Google Desktop
C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll(N/A, N/A)
==================================
Autorun.inf
[E:\]
[AutoRun]
open=AutoRun.exe
shellexecute=AutoRun.exe
shell\打开(&O)\command=AutoRun.exe
==================================
HOSTS 文件
127.0.0.1 localhost
你好aaaaaaa - 2007-8-30 18:09:00
还有注册表给改了“shell Explorer.exe webhelp.exe"
"AlppInit_Dlls wlhpri.dll
请问怎么改回来
有毒必问 - 2007-8-30 18:41:00
你中的病毒很多、、、你说的先参考关于最近流行的dhbpri.dll(***pri.dll)等木马群的查杀(8.9.更新
nkevin - 2007-8-30 19:48:00
安装“雨林木风 PE 工具箱”,重启进入PE 系统
和XP的操作一样,右键删除如下文件:
Internet.Exe
C:\windows\cmdbcs.exe
C:\windows\AVPSrv.exe
C:\Program Files\NetMeeting\avpms.exe
C:\Program Files\NetMeeting\avpms.exe
%systemroot%\system32\a8mw.dll
%systemroot%\system32\wuxztt.dll
systemroot%\system32\hvxtxh74.dll
C:\windows\system32\winsys16_070830.dll
webhelp.exe
C:\windows\system32\ztaman.dll
C:\windows\system32\wlhpri.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys
C:\Program Files\Internet Explorer\IEXPLORE32.Sys
C:\Program Files\Internet Explorer\IEXPLORE32.Dat
C:\Program Files\Internet Explorer\IEXPLORE32.win
服务:
[219829DA / 219829DA]
<C:\windows\system32\D401AB94.EXE
[svchost / svchost]
<C:\windows\system32\dllcache\svchost.exe -g><
[Windows Media Server / Windows Media Server]
<C:\windows\services.exe><N/A>
[8kx6ajgsw / 8kx6ajgsw]
<\??\C:\windows\system32\drivers\8kx6ajgsw.sys><N/A>
然后还是在PE下,删除各个分区下面的autorun.inf和autorun.exe
没有目录的文件,在PE下面用“搜索”(和xp一样的),可以搜索到的,然后删除就是了。
system32目录下的 xxxpri.dll,用通配符搜索,凡是符合 pri.dll的文件,一律删除!
驱动文件,我没细挑。有许多没见过的,等待其他高手帮你挑挑吧。
你删除了上面那些文件后,appini的值会自己改为正常的。
woaaaaa - 2007-8-30 20:19:00
你中的毒和我的一样多啊!我是重装系统才可以用的
你好aaaaaaa - 2007-8-30 23:24:00
可不可以具体说说那个文件是毒?谢谢大家
hotboy - 2007-8-31 1:28:00
卡巴斯基是摆样子的么
你好aaaaaaa - 2007-8-31 2:27:00
我用卡巴斯基 杀了3个毒,电脑也是一样不可以用
feiyu621 - 2007-8-31 10:22:00
看来大家最近中的都一样啊,我郁闷了,我的注册表也被改了,我重新装了系统也没用,现在也没人解救我,QQ都不敢上,家里的电脑就给废了一样.......
你好aaaaaaa - 2007-8-31 11:15:00
去下个魔法兔子,应该可以帮到你
大百科 - 2007-8-31 11:36:00
安装版主的帖子操作
http://forum.ikaka.com/topic.asp?board=28&artid=8360878
hotboy - 2007-8-31 12:41:00
| 引用: |
【你好aaaaaaa的贴子】我用卡巴斯基 杀了3个毒,电脑也是一样不可以用 ……………… |
平时不开监控的么?这个毒卡巴很早就能启发掉了
一根蔗 - 2007-8-31 13:16:00
到瑞星主站上下“注册表恢复”和瑞星公测版,卡巴卸了再装瑞星,用"注册表恢复”恢复
开怀不笑 - 2007-9-1 2:29:00
如果实在杀不了的话就只能重新安装系统了,然后再下载08版瑞星来查杀
失败的风 - 2007-9-1 15:10:00
有主动防御的瑞星杀起毒来效果很是不错的,建议试试看。
最恨病毒NO1 - 2007-9-1 20:55:00
呵呵 我也一个样,最近病毒很多啊,我被我爸骂死了
1
© 2000 - 2026 Rising Corp. Ltd.