瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的电脑中了backdoor.bifrose.fw病毒,怎么也杀不掉!(附日志)

12   1  /  2  页   跳转

我的电脑中了backdoor.bifrose.fw病毒,怎么也杀不掉!(附日志)

我的电脑中了backdoor.bifrose.fw病毒,怎么也杀不掉!(附日志)

我的电脑中了backdoor.bifrose.fw病毒,怎么也杀不掉!
用瑞星,提示“清除成功”,可重启后病毒依旧。
另还中了Trojan.spy.banker.fcz病毒,瑞星,提示“删除成功”,但重启后病毒依旧

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      11:21:04, 日期 06-4-6
操作系统:  Windows 98 SE (Win9x 4.10.2222A)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\YAHOO!\ASSISTANT\YLIVE.EXE
C:\PROGRAM FILES\ZARVASOFT\SMART UPDATE UTILITY\AHNSD.EXE
C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\RISING\RAV\RAV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\ODC\HIJACKTHIS1991ZWW.EXE

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - 启动项HKLM\\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [SystemTray] SysTray.Exe
O4 - 启动项HKLM\\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\YAHOO!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [AHNSD] "C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe"
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE"
O4 - 启动项HKLM\\Run: [nwiz32] c:\windows\system\nwiz32.exe
O4 - 启动项HKLM\\Run: [LoadQM] loadqm.exe
O4 - 启动项HKLM\\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\RunServices: [RsCcenter] "C:\Program Files\Rising\Rav\CCenter.exe"
O4 - 启动项HKLM\\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - 启动项HKLM\\RunServices: [SchedulingAgent] mstask.exe
O4 - 启动项HKLM\\RunServices: [Intnet] C:\WINDOWS\Intnet.exe
O4 - 启动项HKLM\\RunServices: [kavsvc] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll919602] regsvr32 /s C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL/246
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) - res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YRSS.DLL/YRSSMENUEXT
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 202.101.103.54,202.101.103.55

最后编辑2006-04-07 10:30:04
分享到:
gototop
 

就是,麻烦的病毒,还是重新做系统,如果有Ghost 还原也可以!
gototop
 

这是这几天瑞星的扫描结果

病毒名称    处理结果    发现日期    扫描方式    路径    文件
Backdoor.Bifrose.fw    清除成功    2006-03-24 10:58    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Trojan.Spy.Banker.fcz    删除成功    2006-03-24 11:01    手动扫描    C:\WINDOWS\SYSTEM    nwiz32.dll
Trojan.PSW.LMir.jkb    删除成功    2006-03-24 11:11    手动扫描    C:\WINDOWS    29831.DLL
Trojan.PSW.LMir.jkb    删除成功    2006-03-24 11:22    手动扫描    C:\RECYCLED    DC0.EXE
Trojan.PSW.GamePass.al    删除成功    2006-03-24 11:22    手动扫描    C:\RECYCLED    DC1.EXE
Trojan.Spy.Banker.fcz    删除成功    2006-03-27 11:18    定时扫描    C:\WINDOWS\SYSTEM    nwiz32.dll
Trojan.DL.Small.cux    删除成功    2006-03-27 11:22    定时扫描    C:\WINDOWS\Downloaded Program Files    StoreProtect.dll
Backdoor.Bifrose.fw    清除成功    2006-03-27 16:55    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Trojan.Spy.Banker.fcz    删除成功    2006-03-27 16:57    手动扫描    C:\WINDOWS\SYSTEM    nwiz32.dll
Backdoor.Bifrose.fw    清除成功    2006-03-28 09:22    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-03-28 16:09    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-03-28 16:15    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-03-28 16:52    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-03-29 09:27    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-04-03 13:39    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-04-04 09:18    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-04-05 09:30    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Backdoor.Bifrose.fw    清除成功    2006-04-05 10:42    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Trojan.Spy.Banker.fcz    删除成功    2006-04-05 10:44    手动扫描    C:\WINDOWS\SYSTEM    nwiz32.dll
Trojan.Spy.Banker.fcz    删除成功    2006-04-05 11:17    定时扫描    C:\WINDOWS\SYSTEM    nwiz32.dll
Trojan.Spy.Banker.fcz    删除成功    2006-04-05 14:09    手动扫描    C:\WINDOWS\SYSTEM    nwiz32.dll
Backdoor.Bifrose.fw    清除成功    2006-04-06 10:50    手动扫描    IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE   
Trojan.Spy.Banker.fcz    删除成功    2006-04-06 10:53    手动扫描    C:\WINDOWS\SYSTEM    nwiz32.dll
Trojan.PSW.GamePass.bm    删除成功    2006-04-06 11:06    手动扫描    C:\Program Files\Internet Explorer    test.exe
gototop
 

斑主,能不能赶紧帮忙解决,万分感谢!!
gototop
 

【回复“enjoy30”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载System Repair Engineer 2.0.12.350
导出全部日志
gototop
 

SRENG日志

2006-04-07,09:19:07

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows 98 Second Edition

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <msnmsgr><"C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <ScanRegistry><C:\WINDOWS\scanregw.exe /autorun>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TaskMonitor><C:\WINDOWS\taskmon.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <internat.exe><internat.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SystemTray><SysTray.Exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <helper.dll><C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <YLive.exe><C:\PROGRA~1\YAHOO!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <AHNSD><"C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <yassistse><"C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <nwiz32><c:\windows\system\nwiz32.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <LoadQM><loadqm.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KAVPersonal50><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  <YahooC:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll533217><regsvr32 /s C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\yasbar.dll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
  <RsCcenter><"C:\Program Files\Rising\Rav\CCenter.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
  <LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
  <SchedulingAgent><mstask.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
  <Intnet><C:\WINDOWS\Intnet.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
  <kavsvc><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe">

==================================
启动文件夹
服务

==================================
浏览器加载项
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL, Yahoo!>
[DragSearch]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL,  >
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL, Yahoo.>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[寻宝乐趣多]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[Yahoo 1G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8A.OCX, Macromedia, Inc.>
[MsnMessengerSetupDownloadControl Class]
  {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNMESSENGERSETUPDOWNLOADER.OCX, Microsoft Corporation>
[雅虎搜索]
  <res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL/246, N/A>
[添加到QQ自定义面板]
  <C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm, N/A>
[上传到QQ网络硬盘]
  <C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YRSS.DLL/YRSSMENUEXT, N/A>

gototop
 

继续

==================================
正在运行的进程
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294963297][C:\WINDOWS\SYSTEM\MPREXE.EXE]  <Microsoft Corporation><4.10.1998>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
[PID: 4294945421][C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294852237][C:\WINDOWS\SYSTEM\MSTASK.EXE]  <Microsoft Corporation><4.71.1972.1>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL]  <Yahoo! China><1, 1, 2, 1034>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL]  < ><1, 2, 7, 1006>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL]  <Yahoo!><2, 1, 5, 1045>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL]  < ><2, 0, 0, 1006>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL]  <$><2, 0, 5, 1031>
    [C:\PROGRAM FILES\3721\AUTOLIVE.DLL]  <$><1, 1, 4, 1026>
    [C:\WINDOWS\SYSTEM\RAVEXT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\3721\ALREX.DLL]  <$><1, 0, 1, 1001>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294949709][C:\WINDOWS\EXPLORER.EXE]  <Microsoft Corporation><4.72.3110.1>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMINEX.DLL]  <国风因特软件(北京)有限公司><1, 0, 2, 8>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSIO.DLL]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMINIO.DLL]  <北京三七二一科技有限公司><1, 0, 3, 6>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294900565][C:\WINDOWS\RUNDLL32.EXE]  <Microsoft Corporation><4.10.1998>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4292937077][C:\WINDOWS\SYSTEM\RPCSS.EXE]  <Microsoft Corporation><4.71.2900>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
    [C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4292979381][C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4292983097][C:\WINDOWS\TASKMON.EXE]  <Microsoft Corporation><4.10.1998>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4292890509][C:\WINDOWS\SYSTEM\INTERNAT.EXE]  <Microsoft Corporation><4.10.2222>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
[PID: 4292886797][C:\WINDOWS\SYSTEM\SYSTRAY.EXE]  <Microsoft Corporation><4.10.2222>
    [C:\PROGRAM FILES\3721\NOTIFIER.DLL]  <$><1, 0, 0, 5>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\3721\AUTOLIVE.DLL]  <$><1, 1, 4, 1026>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
[PID: 4292900181][C:\WINDOWS\RUNDLL32.EXE]  <Microsoft Corporation><4.10.1998>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YNOTIFIER.DLL]  <$><1, 0, 0, 5>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL]  < ><2, 0, 0, 1006>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL]  <$><2, 0, 5, 1031>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
[PID: 4292873141][C:\PROGRAM FILES\YAHOO!\ASSISTANT\YLIVE.EXE]  < ><2, 0, 0, 1002>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\ZARVASOFT\SMART UPDATE UTILITY\NLS\ASD0804.NLS]  <AhnLab, Inc.><5, 0, 0, 5>
[PID: 4292877185][C:\PROGRAM FILES\ZARVASOFT\SMART UPDATE UTILITY\AHNSD.EXE]  <AhnLab, Inc.><5, 3, 0, 23>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YASMENU.DLL]  <Yahoo><1, 0, 1, 1006>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YIEANGEL.DLL]  <Yahoo><1, 0, 1, 1001>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YMENUINFO.DLL]  <Yahoo><1, 0, 0, 2>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL]  <Yahoo><1, 0, 2, 1002>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
[PID: 4292881365][C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE]  <Yahoo!><1, 0, 1, 1001>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
[PID: 4292906345][C:\WINDOWS\LOADQM.EXE]  <Microsoft Corporation><5.4.1103.3>
    [C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8A.OCX]  <Macromedia, Inc.><8,0,24,0>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
    [C:\WINDOWS\SYSTEM\DCIMAN32.DLL]  <Intel(R) Corp., Microsoft Corp.><4.03.1998>
[PID: 4293090489][C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE]  <Microsoft Corporation><7.0.0816>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
[PID: 4293048313][C:\WINDOWS\SYSTEM\WMIEXE.EXE]  <Microsoft Corporation><5.00.1755.1>
gototop
 

还有

    [C:\PROGRAM FILES\RISING\RAV\EXTFILE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\PROGRAM FILES\RISING\RAV\RSSTORE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\PROGRAM FILES\RISING\RAV\EXTOLE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RAV\EXTMAIL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\PROGRAM FILES\RISING\RAV\NVFILE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\PROGRAM FILES\RISING\RAV\POSTTRTX.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 1>
    [C:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RAV\SCANEX.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\PROGRAM FILES\RISING\RAV\UNEXE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\PROGRAM FILES\RISING\RAV\ENGINE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\PROGRAM FILES\RISING\RAV\MVENGINE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\PROGRAM FILES\RISING\RAV\RAVUIMSG.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
    [C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RAV\RAVUI.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 53>
    [C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
    [C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\PROGRAM FILES\RISING\RAV\PLUGIN\RSPGSCAN.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 4293155085][C:\PROGRAM FILES\RISING\RAV\RAV.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 50>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
[PID: 4293359453][C:\WINDOWS\SYSTEM\DDHELP.EXE]  <Microsoft Corporation><4.06.03.0518>
    [C:\WINDOWS\SYSTEM\RAVEXT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8A.OCX]  <Macromedia, Inc.><8,0,24,0>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSIO.DLL]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMINIO.DLL]  <北京三七二一科技有限公司><1, 0, 3, 6>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YANGLING.DLL]  <Yahoo.><1, 0, 2, 1002>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL]  <Yahoo! China><1, 1, 2, 1034>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YDRAGSEARCH.DLL]  < ><1, 2, 7, 1006>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL]  <Yahoo!><2, 1, 5, 1045>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB FOLDERS\MSONSEXT.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSPLUS.DLL]  <3721><1, 0, 0, 2>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL]  < ><2, 0, 0, 1006>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL]  <$><2, 0, 5, 1031>
    [C:\PROGRAM FILES\3721\AUTOLIVE.DLL]  <$><1, 1, 4, 1026>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHINT.DLL]  <3721><1, 0, 0, 6>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YSCRBLOCK.DLL]  <Yahoo><1, 0, 1, 1000>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\3721\ALREX.DLL]  <$><1, 0, 1, 1001>
    [C:\PROGRAM FILES\3721\SCRBLOCK.DLL]  <3721><1, 0, 1, 1000>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
[PID: 4293315309][C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2800.1106>
    [C:\WINDOWS\SYSTEM\NWIZ32.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL]  <北京三七二一科技有限公司><1, 5, 2, 8>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL]  <$><2, 0, 0, 1013>
    [C:\PROGRAM FILES\3721\HELPER.DLL]  <$><1, 0, 9, 1324>
[PID: 4293410417][C:\MY DOCUMENTS\ODC\SRENG.EXE]  <Smallfrogs Studio><2.0.12.350>

==================================
文件关联
.TXT  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [C:\WINDOWS\winhlp32.exe %1]
.INI  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

【回复“enjoy30”的帖子】
开始--运行
输入regedit
确定
进入注册表
删除如下几项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz32><c:\windows\system\nwiz32.exe>

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Intnet><C:\WINDOWS\Intnet.exe>

=================

另外
C:\WINDOWS\SYSTEM\NWIZ32.DLL
插入到多个系统进程中
既然楼主使用的是WIN98
就可以进入纯DOS下
删除
C:\WINDOWS\SYSTEM\NWIZ32.DLL
c:\windows\system\nwiz32.exe
C:\WINDOWS\Intnet.exe
gototop
 

今天早上一开机扫描这两个病毒还在,晕~~~~
Backdoor.Bifrose.fw清除成功2006-04-07 09:09手动扫描IEXPLORE.EXE>>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Trojan.Spy.Banker.fcz删除成功2006-04-07 09:12手动扫描C:\WINDOWS\SYSTEMnwiz32.dll
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT