【回复“荧惑”的帖子】
6楼开始的这份日志,如果是用专杀杀毒后扫的,那只能说————这个专杀不行!
SRENG日志中的异常内容(病毒群的):
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><qhbpri.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><> [N/A]
<{26368135-64FA-BC34-DA32-DCF4FD431C92}><C:\WINDOWS\system32\qhbpri.dll> []
<{91B1E846-2BEF-4345-8848-7699C7C9935F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll> []
<{30010463-0463-0019-6300-463014630019}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\04630019.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<UPnPMonitor><?{e57ce738-33e8-4c51-8354-bb4de9d215d1}> [N/A]
服务
[System Security / AtWork][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\bbuom.dll><Microsoft Corporation>
[Windows qwsm RunThem / qwsm][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\lrnh\vbxr.dll>< >
[Windows Install Helper / SoSCAR][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE C:\WINDOWS\SYSTEM32\WBEM\AEHHJ.DLL,DllRegisterServer 1087><Microsoft Corporation>
[cdnprot / cdnprot][Stopped/Boot Start]
<\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[DS1410D / DS1410D][Stopped/Auto Start]
<SYSTEM32\drivers\DS1410D.SYS><N/A>
[gdrv / gdrv][Stopped/Manual Start]
<\??\C:\WINDOWS\gdrv.sys><Windows (R) Codename Longhorn DDK provider>
[msqmx / msqmx][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msqmx.sys><N/A>
正在运行的进程
[PID: 704][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
[PID: 752][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 764][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 908][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[PID: 2040][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[c:\progra~1\lrnh\yeau.dll] [, 5, 0, 0, 4]
[c:\progra~1\lrnh\djfz.dll] [ , 5, 0, 0, 4]
[PID: 476][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[c:\progra~1\lrnh\yeau.dll] [, 5, 0, 0, 4]
[c:\progra~1\lrnh\djfz.dll] [ , 5, 0, 0, 4]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll] [N/A, ]
[PID: 1976][J:\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\qhbpri.dll] [N/A, ]
[c:\progra~1\lrnh\yeau.dll] [, 5, 0, 0, 4]
[c:\progra~1\lrnh\djfz.dll] [ , 5, 0, 0, 4]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll] [N/A, ]
==================================
Autorun.inf
[D:\]
[AutoRun]
open=04630019.exe
shell\open=打开(&O)
shell\open\Command=04630019.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=04630019.exe
[E:\]
[AutoRun]
open=04630019.exe
shell\open=打开(&O)
shell\open\Command=04630019.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=04630019.exe
[F:\]
[AutoRun]
open=04630019.exe
shell\open=打开(&O)
shell\open\Command=04630019.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=04630019.exe
[G:\]
[AutoRun]
open=04630019.exe
shell\open=打开(&O)
shell\open\Command=04630019.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=04630019.exe
[H:\]
[AutoRun]
open=04630019.exe
shell\open=打开(&O)
shell\open\Command=04630019.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=04630019.exe