1234   2  /  4  页   跳转

急死人了!!!!!!!!1

浏览器加载项
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll, yahoo! china>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <F:\新建文件夹 (3)\BitComet\tools\BitCometBHO_1.1.3.28.dll, N/A>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL, yahoo! china>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD>
[yFlashDl Class]
  {F166BC04-3C84-44cc-A6E9-2315EC4844B9} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yflashdl.dll, Yahoo! China>
[assist]
  {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll, Yahoo! China>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew, N/A>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[金山毒霸在线产品升级]
  {E847C78C-C210-4195-8799-FBF3BF89797D} <C:\PROGRA~1\KOS\KOSInit.OCX, 金山软件股份有限公司>
[VqqSpeedDlProxy Class]
  {F138084D-84D7-48CD-BEA8-04772457516E} <C:\WINDOWS\vqqsdl.dll, Tencent>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll, yahoo! china>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <F:\新建文件夹 (3)\BitComet\tools\BitCometBHO_1.1.3.28.dll, N/A>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
[Yahoo!Live]
  {57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll, yahoo! china>
[金山毒霸在线杀毒]
  {577A1997-6FD0-4972-B234-885DA583F9CE} <C:\PROGRA~1\KOS\KOSClean.OCX, 金山软件股份有限公司>
[DragSearch BHO]
  {62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL, yahoo! china>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[金山毒霸在线产品升级]
  {E847C78C-C210-4195-8799-FBF3BF89797D} <C:\PROGRA~1\KOS\KOSInit.OCX, 金山软件股份有限公司>
[VqqSpeedDlProxy Class]
  {F138084D-84D7-48CD-BEA8-04772457516E} <C:\WINDOWS\vqqsdl.dll, Tencent>
[yFlashDl Class]
  {F166BC04-3C84-44CC-A6E9-2315EC4844B9} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yflashdl.dll, Yahoo! China>
[assist]
  {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll, Yahoo! China>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
gototop
 

tel.xls.exe 这个是老毒了  随便到网上查一下就能解决
前几天我电脑也中了来着 呵呵 搞笑
gototop
 

正在运行的进程
[PID: 456][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 572][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 584][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll]  [N/A, ]
    [C:\Program Files\Media Player Classic\Codecs\mkunicode.dll]  [N/A, ]
    [C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll]  [Nero AG, 2, 0, 0, 8]
    [C:\Program Files\Common Files\Ahead\Lib\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 6, 7, 1122]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 1]
    [C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll]  [Nero AG, 2, 7, 3, 2]
    [C:\Program Files\Nero\Nero 7\Nero BackItUp\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll]  [Yahoo! China, 3, 0, 8, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 6, 1008]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yflashdl.dll]  [Yahoo! China, 3, 0, 1, 1013]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll]  [Yahoo! China, 3, 1, 8, 1023]
[PID: 968][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.34]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 996][C:\WINDOWS\VM303_STI.EXE]  [Vimicro, 4, 3, 625, 61]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
[PID: 1048][F:\新建文件夹\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
    [F:\新建文件夹\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
[PID: 1040][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe]  [Yahoo! China, 3, 2, 2, 1028]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 6, 7, 1122]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll]  [yahoo! china, 3, 0, 2, 1002]
[PID: 1172][C:\progra~1\yahoo!\assistant\yassistse.exe]  [Yahoo! China, 3, 0, 7, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\progra~1\yahoo!\assistant\shell\yAssecblk.dll]  [Yahoo! China, 3, 1, 9, 1027]
    [C:\progra~1\yahoo!\assistant\shell\yAsMenu.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\progra~1\yahoo!\assistant\shell\yMenuInfo.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\progra~1\yahoo!\assistant\shell\yIEAngel.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
gototop
 

[PID: 1240][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1376][C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll]  [Nero AG, 7,7,0, 10200]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 1, 7, 11, 0]
[PID: 1552][C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMSQLDB.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll]  [Nero AG, 1, 0, 0, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMCoFoundation.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMFullTextExtraction.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NeroIPP.dll]  [Nero AG, 4,6,15,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 1, 7, 11, 0]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll]  [Nero AG, 1, 7, 11, 0]
[PID: 3068][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 6, 7, 1122]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 3, 6, 1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ysearch.dll]  [Yahoo! China, 3, 1, 9, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll]  [Yahoo! China, 3, 0, 8, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll]  [Yahoo! China, 3, 0, 4, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yaswiper.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasiesec.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YSETTI~1.DLL]  [yahoo! china, 3, 1, 9, 1033]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymailp.dll]  [Yahoo! China, 3, 0, 6, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymyweb.dll]  [Yahoo! China, 3, 0, 4, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll]  [yahoo! china, 3, 0, 5, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 6, 1008]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yflashdl.dll]  [Yahoo! China, 3, 0, 1, 1013]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll]  [Yahoo! China, 3, 1, 8, 1023]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\PROGRA~1\KOS\KOSInit.OCX]  [金山软件股份有限公司, 2007, 4, 29, 3]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3100 (xpsp_sp2_gdr.070309-0025)]
    [C:\PROGRA~1\KOS\KOSClean.OCX]  [金山软件股份有限公司, 2007, 4, 20, 2]
    [C:\PROGRA~1\KOS\KASData.dll]  [Kingsoft Corporation, 2007, 2, 11, 32]
    [C:\PROGRA~1\KOS\Extend\KASExt.KAS]  [Kingsoft Corporation, 2007, 5, 11, 151]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [C:\PROGRA~1\KOS\KAEScan.DLL]  [Kingsoft Corp., 2006, 11, 16, 1]
    [C:\PROGRA~1\KOS\KAEPlat.DLL]  [Kingsoft Corp., 2007, 2, 4, 61]
    [C:\PROGRA~1\KOS\KAEMem.DAT]  [Kingsoft, 2006, 9, 11, 15]
    [C:\PROGRA~1\KOS\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 4, 12, 116]
    [C:\PROGRA~1\KOS\KAVKFile.dll]  [N/A, ]
    [C:\PROGRA~1\KOS\KAEMemEx.dll]  [, 2006, 10, 17, 16]
    [C:\PROGRA~1\KOS\KAEMalDt.dll]  [, 2006, 12, 7, 20]
    [C:\PROGRA~1\KOS\KAERemov.dll]  [, 2007, 2, 5, 26]
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  [Macromedia, Inc., 8,0,24,0]
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  [Yahoo! China, 3, 1, 9, 1027]
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yxpstyle.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrepair.dll]  [Yahoo! China, 3, 0, 9, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasfsks.dll]  [Yahoo! China, 2, 1, 3, 89]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yoptimum.dll]  [Yahoo! China, 3, 0, 2, 1006]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
[PID: 2804][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 6, 7, 1122]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 3, 6, 1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ysearch.dll]  [Yahoo! China, 3, 1, 9, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll]  [Yahoo! China, 3, 0, 8, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll]  [Yahoo! China, 3, 0, 4, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yaswiper.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasiesec.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YSETTI~1.DLL]  [yahoo! china, 3, 1, 9, 1033]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymailp.dll]  [Yahoo! China, 3, 0, 6, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymyweb.dll]  [Yahoo! China, 3, 0, 4, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll]  [yahoo! china, 3, 0, 5, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 6, 1008]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yflashdl.dll]  [Yahoo! China, 3, 0, 1, 1013]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll]  [Yahoo! China, 3, 1, 8, 1023]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\PROGRA~1\KOS\KOSInit.OCX]  [金山软件股份有限公司, 2007, 4, 29, 3]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3100 (xpsp_sp2_gdr.070309-0025)]
    [C:\PROGRA~1\KOS\KOSClean.OCX]  [金山软件股份有限公司, 2007, 4, 20, 2]
    [C:\PROGRA~1\KOS\KASEngine.dll]  [Kingsoft Corporation, 2007, 4, 4, 109]
    [C:\PROGRA~1\KOS\KASData.dll]  [Kingsoft Corporation, 2007, 2, 11, 32]
    [C:\PROGRA~1\KOS\Extend\KASExt.KAS]  [Kingsoft Corporation, 2007, 5, 11, 151]
    [C:\PROGRA~1\KOS\KAEMemEx.dll]  [, 2006, 10, 17, 16]
    [C:\PROGRA~1\KOS\KAEMalDt.dll]  [, 2006, 12, 7, 20]
    [C:\PROGRA~1\KOS\KAERemov.dll]  [, 2007, 2, 5, 26]
[PID: 2744][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 692][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3748][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX13.844\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[D:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[E:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[F:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

[PID: 1240][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1376][C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll]  [Nero AG, 7,7,0, 10200]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 1, 7, 11, 0]
[PID: 1552][C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMSQLDB.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll]  [Nero AG, 1, 0, 0, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMCoFoundation.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMFullTextExtraction.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll]  [Nero AG, 1, 7, 11, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NeroIPP.dll]  [Nero AG, 4,6,15,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 1, 7, 11, 0]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexingServicePS.dll]  [Nero AG, 1, 7, 11, 0]
[PID: 3068][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 6, 7, 1122]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 3, 6, 1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ysearch.dll]  [Yahoo! China, 3, 1, 9, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll]  [Yahoo! China, 3, 0, 8, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll]  [Yahoo! China, 3, 0, 4, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yaswiper.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasiesec.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YSETTI~1.DLL]  [yahoo! china, 3, 1, 9, 1033]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymailp.dll]  [Yahoo! China, 3, 0, 6, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymyweb.dll]  [Yahoo! China, 3, 0, 4, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll]  [yahoo! china, 3, 0, 5, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 6, 1008]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yflashdl.dll]  [Yahoo! China, 3, 0, 1, 1013]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll]  [Yahoo! China, 3, 1, 8, 1023]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\PROGRA~1\KOS\KOSInit.OCX]  [金山软件股份有限公司, 2007, 4, 29, 3]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3100 (xpsp_sp2_gdr.070309-0025)]
    [C:\PROGRA~1\KOS\KOSClean.OCX]  [金山软件股份有限公司, 2007, 4, 20, 2]
    [C:\PROGRA~1\KOS\KASData.dll]  [Kingsoft Corporation, 2007, 2, 11, 32]
    [C:\PROGRA~1\KOS\Extend\KASExt.KAS]  [Kingsoft Corporation, 2007, 5, 11, 151]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [C:\PROGRA~1\KOS\KAEScan.DLL]  [Kingsoft Corp., 2006, 11, 16, 1]
    [C:\PROGRA~1\KOS\KAEPlat.DLL]  [Kingsoft Corp., 2007, 2, 4, 61]
    [C:\PROGRA~1\KOS\KAEMem.DAT]  [Kingsoft, 2006, 9, 11, 15]
    [C:\PROGRA~1\KOS\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 4, 12, 116]
    [C:\PROGRA~1\KOS\KAVKFile.dll]  [N/A, ]
    [C:\PROGRA~1\KOS\KAEMemEx.dll]  [, 2006, 10, 17, 16]
    [C:\PROGRA~1\KOS\KAEMalDt.dll]  [, 2006, 12, 7, 20]
    [C:\PROGRA~1\KOS\KAERemov.dll]  [, 2007, 2, 5, 26]
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  [Macromedia, Inc., 8,0,24,0]
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  [Yahoo! China, 3, 1, 9, 1027]
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yxpstyle.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrepair.dll]  [Yahoo! China, 3, 0, 9, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasfsks.dll]  [Yahoo! China, 2, 1, 3, 89]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yoptimum.dll]  [Yahoo! China, 3, 0, 2, 1006]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
[PID: 2804][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [yahoo! china, 3, 6, 7, 1122]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 3, 6, 1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ysearch.dll]  [Yahoo! China, 3, 1, 9, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll]  [Yahoo! China, 3, 0, 8, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll]  [Yahoo! China, 3, 0, 4, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yaswiper.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasiesec.dll]  [Yahoo! China, 3, 0, 6, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YSETTI~1.DLL]  [yahoo! china, 3, 1, 9, 1033]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymailp.dll]  [Yahoo! China, 3, 0, 6, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ymyweb.dll]  [Yahoo! China, 3, 0, 4, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll]  [yahoo! china, 3, 0, 5, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 6, 1008]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yflashdl.dll]  [Yahoo! China, 3, 0, 1, 1013]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll]  [Yahoo! China, 3, 1, 8, 1023]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\PROGRA~1\KOS\KOSInit.OCX]  [金山软件股份有限公司, 2007, 4, 29, 3]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3100 (xpsp_sp2_gdr.070309-0025)]
    [C:\PROGRA~1\KOS\KOSClean.OCX]  [金山软件股份有限公司, 2007, 4, 20, 2]
    [C:\PROGRA~1\KOS\KASEngine.dll]  [Kingsoft Corporation, 2007, 4, 4, 109]
    [C:\PROGRA~1\KOS\KASData.dll]  [Kingsoft Corporation, 2007, 2, 11, 32]
    [C:\PROGRA~1\KOS\Extend\KASExt.KAS]  [Kingsoft Corporation, 2007, 5, 11, 151]
    [C:\PROGRA~1\KOS\KAEMemEx.dll]  [, 2006, 10, 17, 16]
    [C:\PROGRA~1\KOS\KAEMalDt.dll]  [, 2006, 12, 7, 20]
    [C:\PROGRA~1\KOS\KAERemov.dll]  [, 2007, 2, 5, 26]
[PID: 2744][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 692][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3748][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX13.844\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 8, 1026]
    [F:\新建文件夹\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[D:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[E:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[F:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

看看是哪有问题呀本人急呀
gototop
 

随便搜了下 你试试吧
注意 在任务管理器的应用程序里 因该有个EXCEL的东西在运行 仿佛版本不同 名字也不同的 这个也要结束掉的



tel.xls.exe
病毒类型:木 马
影响系统:Win 9x/ME,Win 2000/NT,Win XP,Win 2003
病毒行为:盗取QQ帐号密码的木马病毒,特点是可以通过可移动磁盘传播。
        该病毒的主要危害是盗取QQ帐户和密码,盗取方式为键盘记录,
        包括软件盘,将盗取的号码和密码通过邮件发送到指定邮箱。 

1.生成文件

%systemroot%\SocksA.exe

非系统盘下 tel.xls.exe和autorun.inf

autorun.ini内容:
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe

2.注册表

(1)添加启动项

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ASocksrv" = "SocksA.exe"
更改文件夹选项中显示隐藏文件的值

HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue 的类型为REG_SZ(原本为REG_DWORD)感染病毒后,系统将不再显示隐藏文件和扩展名,同时tel.xls.exe也伪装成为EXCEL的图标,诱导用户点击导致深度感染。当用户双击打开磁盘时,autorun.ini使tel.xls.exe自动运
行。 查杀方法:

1.删除驻留的病毒程序:打开"任务管理器",找到tel.xls.exe和SocksA.exe进程,把它们

结束掉。到C:\WINDOWS\system32里找到SocksA.exe把它删除。如果无法删除,使用

killbox选择重启删除,或进入安全模式删除。

2.禁用移动设备的自动运行功能(目的在于避免重新被U盘感染):把下面的代码保存为

noautorun.reg,导入注册表即可。
Windows Registry Editor Version 5.00[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=dword:000000ff
3.恢复显示所有的文件项:打开regedit,找到

HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\explorer\
Advanced\Folder\Hidden\SHOWALL中的CheckedValue,检查它的类型是否为REG_DWORD,如果不是则删掉 CheckedValue,然后单击右键"新建" - "Dword值",并命名为CheckedValue,然后修改它的键值为1。
4.删除病毒文件:打开"文件夹选项" - "查看",选择"显示所有文件和文件夹",并把"隐藏受保护的系统文件"复选框的√去除。在各磁盘上用右键选择"打开",删除各个非系统盘根目录下的autorun.inf和tel.xls.exe文件。关于autorun.inf tel.xls.exe两个病毒的查杀

    autorun风暴主程序名称为X:\Recycler\Recycler\autorun.exe(相应目录下还有一desktop.ini使得双击

后指向回收站……)同时还有同名的vbs/bat等文件。tel.xls.exe主程序即为此,中毒症状为进程中出现名

为kill的excel图标进程也是通过根目录的autorun.inf进行启动两个病毒均可被卡巴截杀中毒的都可以通过

安全模式的全盘扫描来根治。


------------------------------------
||手动查杀方法||
1.打开"任务管理器",找到tel.xls.exe和SocksA.exe进程,把它们结束掉。到 C:\WINDOWS\system32里找到SocksA.exe把它删除。
2.执行"开始"-"运行"-输入"regedit"打开注册表
3.找到HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\explorer\A
  dvanced\Folder\Hidden\SHOWALL中的CheckedValue,检查它的类型是否为REG_DWORD
  如果不是则删掉CheckedValue,然后单击右键"新建" - "Dword值",并命名为
  CheckedValue,然后修改它的键值为1。
4.打开"我的电脑" - "工具" - "文件夹选项" - "查看",
  选择"显示所有文件和文件夹",
  并把"隐藏受保护的系统文件"复选框的√去除。
5.关闭任务管理器里的explorer.exe,选“文件”新建任务cmd,然后输入
  del C:\autorun.inf/f/s/q/a和del C:\tel.xls.exe/f/s/q/a,
  然后D盘,相同操作,有几个盘杀几个盘。然后用SREng把启动项目里的
  SocksA.exe删掉,msconfig也行吧
6.重新启动计算机。

gototop
 

上面有没有写删除FILEKEN.EXE?
如果没有 你顺手就把它也干掉吧

最好到安全模式下去做
gototop
 

不明白呀是不是不用第一种方法用第二种就行了!  还有手动中的第5点不懂呀结束桌面就看不到了  新建任务时输入要直接还是 分行输入  什么有几个盘杀几个盘呀不懂! 什么又是SREng  启动项又是什么?
gototop
 

就是说你有几个盘就删几次。如果你只有C/D/E,就是三个。
桌面看不到了就在任务管理器的文件里新建CMD呀。
SREng就是你扫日志的软件。有个启动项清理。
gototop
 
1234   2  /  4  页   跳转
页面顶部
Powered by Discuz!NT