j91191 - 2007-11-15 17:14:00
非常感谢你的帮忙!。谢谢
[用户系统信息]Opera/9.24 (Windows NT 5.2; U; zh-cn)
[CODE]
2007-11-15,16:34:43
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows Server 2003 "R2" Enterprise Edition Service Pack 2 (Build 3790) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AudioDeck><C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1> [N/A]
<VTPreset><VTPreset.exe> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<CSPContext><C:\WINDOWS\system32\CSPContext.exe> [N/A]
<OutpostMonitor><C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray> [Agnitum Ltd.]
<OutpostFeedBack><"C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" /dump:os_startup> [Agnitum Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><c:\progra~1\agnitum\outpos~1\wl_hook.dll> [Agnitum Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><%SystemRoot%\system32\logonui.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [(Verified)Microsoft Windows Component Publisher]
==================================
启动文件夹
[快捷方式 到 win2003]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\快捷方式 到 win2003.lnk --> G:\焕\win2003 [N/A]><N>
==================================
服务
[Agnitum Client Security Service / acssrv][Stopped/Auto Start]
<C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe><Agnitum Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
==================================
驱动程序
[Agnitum firewall driver / afw][Running/Manual Start]
<system32\DRIVERS\afw.sys><Agnitum Ltd.>
[ASWFilt / ASWFilt][Running/Manual Start]
<system32\Filt\ASWFilt.dll><Agnitum Ltd.>
[Cdsys / Cdsys][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\cdcd.sys><N/A>
[VIA Rhine Family Fast Ethernet Adapter Driver / FETNDIS][Running/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[S3Psddr / S3Psddr][Running/Manual Start]
<system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
[S3SavageNB / S3SavageNB][Stopped/Manual Start]
<system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
[SandBox / SandBox][Running/System Start]
<system32\DRIVERS\SandBox.sys><Agnitum Ltd.>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
<system32\drivers\vinyl97.sys><VIA Technologies, Inc.>
==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <E:\Program Files\Thunder\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[KPBHO Class]
{7C7DE9B8-CAA6-4B31-BC09-45AFC6B90FDE} <C:\WINDOWS\system32\iesense.dll, N/A>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <E:\Program Files\Thunder\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[Quick Tune]
{44627E97-789B-40d4-B5C2-58BD171129A1} <C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll, Agnitum Ltd.>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\Program Files\Common Files\Kingsoft\Extract\AddIns\IEBand.dll, 金山软件股份有限公司>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <E:\Program Files\Thunder\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Agent Class]
{485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <E:\Program Files\Thunder\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[KPBHO Class]
{7C7DE9B8-CAA6-4B31-BC09-45AFC6B90FDE} <C:\WINDOWS\system32\iesense.dll, N/A>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <E:\Program Files\Thunder\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[使用迅雷下载]
<E:\Program Files\Thunder\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<E:\Program Files\Thunder\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
j91191 - 2007-11-15 17:18:00
==================================
正在运行的进程
[PID: 272 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 320 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 408 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 456 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 468 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 644 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 732 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 796 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 816 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 852 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 1016 / NETWORK SERVICE][C:\WINDOWS\system32\msdtc.exe] [Microsoft Corporation, 2001.12.4720.3959 (srv03_sp2_rtm.070216-1710)]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 1196 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 1384 / CHENG9868][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.3790.3959 (srv03_sp2_rtm.070216-1710)]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[E:\Program Files\Thunder\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16]
[E:\Program Files\Thunder\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 44]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Agnitum\Outpost Firewall Pro\op_shell.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 1620 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 1784 / CHENG9868][C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe] [VIA Technologies, Inc., 6, 3, 4, 0]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 1800 / CHENG9868][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3208]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 1844 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 1860 / CHENG9868][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 2044 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 184 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 332 / NETWORK SERVICE][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[PID: 1136 / CHENG9868][G:\焕\xp\139杀毒工具\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[c:\progra~1\agnitum\outpos~1\wl_hook.dll] [Agnitum Ltd., 6.0.2168.8301]
[G:\焕\xp\139杀毒工具\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
超级游戏迷 - 2007-11-15 20:25:00
一、到http://www.arswp.com/下载最新版本的WINDOWS清理助手;
二、用SRENG扫描工具删除以下项目:
1、驱动程序
[Cdsys / Cdsys][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\cdcd.sys><N/A>
2、浏览器加载项:
[KPBHO Class]
{7C7DE9B8-CAA6-4B31-BC09-45AFC6B90FDE} <C:\WINDOWS\system32\iesense.dll, N/A>
三、重启电脑进入安全模式,双击“我的电脑”--工具--文件夹选项--查看--勾选“显示系统文件和文件夹”,取消勾选“隐藏受保护的操作系统文件(推荐)”,之后勾选“显示所有的文件和文件夹”--确定--找到以下文件,删除(找不到就算了):
C:\WINDOWS\system32\cdcd.sys
C:\WINDOWS\system32\iesense.dll
四、安全模式下运行杀软全盘杀毒,然后运行WINDOWS清理助手,执行“快速扫描”,清理下流氓软件。
超级游戏迷 - 2007-11-15 20:27:00
G:\焕\win2003这个文件是什么DD?为什么要设置为开机启动?楼主自己解决吧。
j91191 - 2007-11-15 21:03:00
谢谢两位!两位关注到的病毒,在系统中没找到,应该是被杀掉了,
我只是觉得在启动项中有几个奇怪的启动项,我电脑再没有软件上网的情况下,居然出现两个奇怪的连接,所以让我感到很害怕!奇怪的启动项如下,请帮忙看看是否正常:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [(Verified)Microsoft Windows Component Publisher]
超级游戏迷 - 2007-11-15 22:13:00
| 引用: |
【j91191的贴子】谢谢两位!两位关注到的病毒,在系统中没找到,应该是被杀掉了, 我只是觉得在启动项中有几个奇怪的启动项,我电脑再没有软件上网的情况下,居然出现两个奇怪的连接,所以让我感到很害怕!奇怪的启动项如下,请帮忙看看是否正常: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [(Verified)Microsoft Windows Component Publisher] ……………… |
个人认为,上面这些通通都是正常的注册表项目,分别是桌面主题、OE(OUTLOOK EXPRESS,XP自带的类QQ即时通讯软件)、WMP(系统自带播放器)的注册表项目,我的也有,新版SRENG扫描出来的DD。
j91191 - 2007-11-15 22:24:00
可是以前我没有这些启动程序的,是8月份后开始有的,并且那之后,要是用系统自带的防火墙就会有某名奇妙的连接连接到SVCHOST,EXE
© 2000 - 2026 Rising Corp. Ltd.