12   1  /  2  页   跳转

是Sreng日志.求助啊!

是Sreng日志.求助啊!

电脑中病毒了,自动弹出对话框说发现病毒,一直弹,即使用GHOST备分还原成原来的系统还是这样,最后完全重装新的系统还是这样,怎么回师啊?
现在是一会一会就弹出对话框,发现的病毒有比如:C:\WINDOWS\System32\msccrt.dll

附件附件:

下载次数:177
文件类型:application/octet-stream
文件大小:
上传时间:2007-10-8 23:11:21
描述:

最后编辑2007-10-11 00:46:11.123000000
分享到:
gototop
 

启动项目
注册表

    <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd>  [N/A]
    <STDSB><C:\WINDOWS\System32\STDSB.exe>  []
    <GenProtect><C:\WINDOWS\gviaul.exe>  []
    <AVPSrv><C:\WINDOWS\AVPSrv.exe>  []
    <NVDispDrv><C:\WINDOWS\NVDispDrv.exe>  [N/A]
    <MsPrint32D><C:\WINDOWS\mpcdxh.exe>  []
    <WinSysM><C:\WINDOWS\IGM.exe>  [N/A]
    <DbgHlp32><C:\WINDOWS\DbgHlp32.exe>  [N/A]
    <Kvsc3><C:\WINDOWS\Kvsc3.exe>  []
    <mppds><C:\WINDOWS\mppds.exe>  []
    <MsIMMs32><C:\WINDOWS\MsIMMs32.exe>  []
    <cmdbcs><C:\WINDOWS\cmdbcs.exe>  []
    <upxdnd><C:\WINDOWS\upxdnd.exe>  []
    <msccrt><C:\WINDOWS\msccrt.exe>  []
    C:\WINDOWS\System32\LYLeador.exe
    C:\WINDOWS\System32\zinforms.dll
    <{AEB6717E-7E19-11d0-97EE-00C04FD91974}><winforms.dll>  [N/A]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91975}><zinforms.dll>  []
==================================
服务
[9DF98F8E / 9DF98F8E][Stopped/Auto Start]
  <C:\WINDOWS\System32\E14E14D.EXE -k><Microsoft Corporation>


==================================
驱动程序

[Scroll Bar Driver / MTC0003_STDSB][Running/Auto Start]
  <System32\STDSB.sys><>


==================================
正在运行的进程
C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]


[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe

水平有限就看到上面这些

1用SRE 点启动项目--服务---WIN32 服务...-----勾上 隐藏已认.... ----找到 [9DF98F8E / 9DF98F8E] 这项 (应该默认第一项了) 点击 再勾上 删除服务---点 设置---否 关闭

点启动项目--服务---驱动程序-----勾上 隐藏已认.... ----找到 Scroll Bar Driver / MTC0003_STDSB 这项  点击 再勾上 删除服务---点 设置---否

下载http://www.i170.com/attach/97670969-F47C-4A8B-9529-F0F602EFA902这个软件 名字是Xdelbox
解压所有文件到一个文件夹 打开Xdelbox
在 添加旁边的框中 分别输入下面的这些 一个一个输 ,输入完一个以后 点击旁边的添加 按钮 被添加的文件 将出现在大框中
    C:\WINDOWS\System32\cmicnfg.cpl
    C:\WINDOWS\System32\CMICtrlWnd
    C:\WINDOWS\System32\STDSB.exe
    C:\WINDOWS\gviaul.exe
    C:\WINDOWS\AVPSrv.exe
    C:\WINDOWS\NVDispDrv.exe
    C:\WINDOWS\mpcdxh.exe
    C:\WINDOWS\IGM.exe
    C:\WINDOWS\DbgHlp32.exe
    C:\WINDOWS\Kvsc3.exe
    C:\WINDOWS\mppds.exe
    C:\WINDOWS\MsIMMs32.exe
    C:\WINDOWS\cmdbcs.exe
    C:\WINDOWS\upxdnd.exe
    C:\WINDOWS\msccrt.exe
    C:\WINDOWS\System32\LYLeador.exe
    C:\WINDOWS\System32\zinforms.dll
    C:\WINDOWS\System32\winforms.dll
    C:\WINDOWS\System32\zinforms.dll


勾上三个勾 然后一次性选中 (按住ctrl)下面大框中所有的文件
右键 单击 点击 重启立即删除
重启计算机以后 会有两个系统进入的选择的倒计时界面
第一个是你原来的windows系统
第二个是我的软件给你设定的dos系统
进入第二个系统
类似dos的界面滚动完毕以后 病毒就被删除了
之后他会自动重启 选择进入正常模式


2重启动电脑
关闭自动播放--->在“开始”菜单的“运行”框中运行“gpedit.msc”命令,在“组策略”找到“计算机配置”和“用户配置”下的“管理模板”功能,打开其中的“系统”菜单中的“关闭自动播放”的设置,在其属性里面选择“已启用”,接着选择“所有驱动器”,最后确定保存即可。

打开SRE  点 系统修复--WINDOWS SHELL /IE---在窗口中找到 显示隐藏文件 前面打勾---点修复

呵呵 在桌面新建个文本  将下面的代码放如其中 保存 将名字改为1.BAT  打开
del /f /q C:\auto.exe
del /f /q C:\autorun.inf
del /f /q d:\auto.exe
del /f /q d:\autorun.inf
del /f /q e:\auto.exe
del /f /q e:\autorun.inf
del 1.bat


再杀毒 后重启动 看看还有没有
gototop
 

我按着你的指示做了,但下面这些不能被选入(显示为:不存在该文件(软件不支持删除文件夹)):
C:\WINDOWS\System32\cmicnfg.cpl
C:\WINDOWS\System32\CMICtrlWnd
C:\WINDOWS\gviaul.exe
C:\WINDOWS\NVDispDrv.exe
C:\WINDOWS\mpcdxh.exe
C:\WINDOWS\IGM.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\System32\LYLeador.exe
C:\WINDOWS\System32\winforms.dll
但我依然按指示,把其他能删的都删了,然后一步步做下去,但最后重启了还是会弹出框说有病毒,还是那些病毒
gototop
 

我查了下,病毒差不多有如下几种:

威胁: Infostealer.Gampass
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\652LPS8Z\mh0618[1].exe

威胁: Trojan.PWS.QQPass
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\N99SKD1Q\dh0616[1].exe

威胁: Infostealer.Gampass
文件:  C:\Documents and Settings\EADING\Local Settings\Teporary Internet Files\Content.IE5\W3ENC3QJ\dh3[1].exe

威胁: Infostealer
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\W3ENC3QJ\wm[1].exe

威胁: Infostealer.Gampass
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\N99SKD1Q\dh3[1].exe
gototop
 



下载 System Repair Engineer系统扫描工具软件,下载地址如下:
http://www.kztechs.com/sreng/download.html
扫描和上传日志的方法:
1、解压缩所下载的sreng2.zip压缩包;
2、打开已经解压缩的SRENG文件夹,双击运行其中的SREngPS.exe;
3、依次按“智能扫描”、“扫描”、“保存报告”,将日志保存到硬盘上;
4、找到并打开日志,把日志中的内容用“复制”--“粘贴”命令拷贝到帖子上,不要修改地传上来(日志很长,一个帖子搞不完,请手动将全部内容在同一个主题帖下分多个回复帖子传上来)。
gototop
 

[CODE]

2007-10-09,20:31:54

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Windows XP Publisher]
    <MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <IgfxTray><C:\WINDOWS\System32\igfxtray.exe>  [(Verified)Microsoft Windows XP Publisher]
    <HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd>  [N/A]
    <STDSB><C:\WINDOWS\System32\STDSB.exe>  [N/A]
    <SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>  [(Verified)Microsoft Windows XP Publisher]
    <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Microsoft Windows XP Publisher]
    <D-Link AirPlus G><C:\Program Files\D-Link\AirPlus G\AirGCFG.exe>  [D-Link]
    <ANIWZCS2Service><C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe>  [Alpha Networks Inc.]
    <ZSSnp211><C:\WINDOWS\ZSSnp211.exe>  [ZSMCSNAP]
    <Domino><C:\WINDOWS\Domino.exe>  []
    <GenProtect><C:\WINDOWS\GenProtect.exe>  []
    <AVPSrv><C:\WINDOWS\AVPSrv.exe>  []
    <NVDispDrv><C:\WINDOWS\nqvrgy.exe>  []
    <MsPrint32D><C:\WINDOWS\MsPrint32D.exe>  []
    <WinSysM><C:\WINDOWS\IGM.exe>  []
    <DbgHlp32><C:\WINDOWS\oxwwii.exe>  []
    <runeip><"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup>  [Beijing Rising Technology Co., Ltd.]
    <Storm2Set><; C:\WINDOWS\System32\rundll32.exe "C:\PROGRA~1\StormII\StormSet.dll",CheckEnv>  [(Verified)Beijing Baofeng Inc.]
    <mppds><C:\WINDOWS\mppds.exe>  []
    <Kvsc3><C:\WINDOWS\Kvsc3.exe>  []
    <cmdbcs><C:\WINDOWS\cmdbcs.exe>  []
    <upxdnd><C:\WINDOWS\upxdnd.exe>  []
    <msccrt><C:\WINDOWS\msccrt.exe>  []
    <MsIMMs32><C:\WINDOWS\MsIMMs32.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <MSDEG32><LYLoader.exe>  []
    <MSDWG32><LYLoadbr.exe>  [N/A]
    <MSDCG32    ><LYLeador.exe>  [N/A]
    <MSDOG32><LYLoador.exe>  [N/A]
    <MSDSG32><LYLoadar.exe>  [N/A]
    <MSDMG32><LYLoadmr.exe>  []
    <MSDHG32><LYLoadhr.exe>  [N/A]
    <MSDQG32><LYLoadqr.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><C:\WINDOWS\System32\zinforms.dll>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91974}><winforms.dll>  []
    <{AEB6717E-7E19-11d0-97EE-00C04FD91975}><zinforms.dll>  []
    <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\System32\shlhook.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
    <N/A><"C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
gototop
 

==================================
启动文件夹
N/A

==================================
服务
[9DF98F8E / 9DF98F8E][Stopped/Auto Start]
  <C:\WINDOWS\System32\E14E14D.EXE -k><Microsoft Corporation>
[ANIWZCSd Service / ANIWZCSdService][Stopped/Auto Start]
  <C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe><Alpha Networks Inc.>
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[SmartLinkService / SLService][Running/Auto Start]
  <slserv.exe><>

==================================
驱动程序
[AliIde / AliIde][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[ANIO Service / ANIO][Running/Auto Start]
  <\??\C:\WINDOWS\System32\ANIO.SYS><Alpha Networks Inc.>
[CmdIde / CmdIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  <system32\drivers\cmuda.sys><C-Media Inc>
[Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start]
  <System32\DRIVERS\e100b325.sys><Intel Corporation>
[VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  <System32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
[GMSIPCI / GMSIPCI][Stopped/Manual Start]
  <\??\G:\INSTALL\GMSIPCI.SYS><N/A>
[ialm / ialm][Running/Manual Start]
  <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[MegaIDE / MegaIDE][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[Mtlmnt5 / Mtlmnt5][Running/Manual Start]
  <System32\DRIVERS\SLDRV\Mtlmnt5.sys><>
[Mtlstrm / Mtlstrm][Stopped/Manual Start]
  <System32\DRIVERS\SLDRV\Mtlstrm.sys><>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\QQ2004\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RecAgent / RecAgent][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\SLDRV\RecAgent.sys><>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
[D-Link USB Wireless LAN Card Driver / RT73][Running/Manual Start]
  <System32\DRIVERS\Dr71WU.sys><Ralink Technology, Corp.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[SmartLink AMR_PCI Driver / Slntamr][Running/Manual Start]
  <System32\DRIVERS\SLDRV\slntamr.sys><>
[SlNtHal / SlNtHal][Stopped/Manual Start]
  <System32\DRIVERS\SLDRV\Slnthal.sys><>
[SlWdmSup / SlWdmSup][Running/Manual Start]
  <System32\DRIVERS\SLDRV\SlWdmSup.sys><>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <System32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera (ZS0211) / ZSMC211][Stopped/Manual Start]
  <System32\Drivers\ZS211.sys><ZSMC Corporation>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
  <system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
  <system32\drivers\ialmkchw.sys><Intel Corporation>
gototop
 

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\QQ2004\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[&Research]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\QQ2004\QQ.EXE, TENCENT>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\QQ2004\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[金山快译(&K)]
  {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\QQ2004\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\QQ2004\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\QQ2004\SendMMS.htm, N/A>

==================================
gototop
 

正在运行的进程
[PID: 560 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 780 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 804 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 852 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\LYMANGR.DLL]  [N/A, ]
[PID: 864 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1032 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1056 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1120 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1144 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
[PID: 1280 / SYSTEM][C:\WINDOWS\system32\slserv.exe]  [ , 4.00.07]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1304 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1396 / LOCAL SERVICE][C:\WINDOWS\System32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1776 / EADING][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 352 / EADING][C:\WINDOWS\System32\hkcmd.exe]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxhk.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 368 / EADING][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 376 / EADING][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynCOM.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynTPAPI.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 392 / EADING][C:\Program Files\D-Link\AirPlus G\AirGCFG.exe]  [D-Link, 3, 3, 1, 51123]
    [C:\WINDOWS\System32\wlanapi.dll]  [Alpha Networks Inc., 1, 3, 36, 51122]
    [C:\WINDOWS\System32\ANIOApi.dll]  [Alpha Networks Inc., 2, 0, 3, 51006]
    [C:\WINDOWS\System32\AQCKGen.dll]  [Alpha Networks Inc., 1, 0, 0, 30603]
    [C:\WINDOWS\System32\WlanApp.dll]  [Alpha Networks Inc., 1, 0, 15, 51118]
    [C:\Program Files\D-Link\AirPlus G\WlanMon.dll]  [D-Link, 3, 3, 1, 50907]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1300 / EADING][C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe]  [Alpha Networks Inc., 1, 0, 6, 41216]
    [C:\WINDOWS\System32\ANIWZCS2.DLL]  [Alpha Networks Inc., 2, 4, 38, 51122]
    [C:\WINDOWS\System32\AQCKGen.dll]  [Alpha Networks Inc., 1, 0, 0, 30603]
    [C:\WINDOWS\System32\ANIOApi.dll]  [Alpha Networks Inc., 2, 0, 3, 51006]
    [C:\WINDOWS\System32\WlanApp.dll]  [Alpha Networks Inc., 1, 0, 15, 51118]
    [C:\WINDOWS\System32\wlanapi.dll]  [Alpha Networks Inc., 1, 3, 36, 51122]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 404 / EADING][C:\WINDOWS\ZSSnp211.exe]  [ZSMCSNAP, 3, 6, 818, 7]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\System32\GenProtect.dll]  [N/A, ]
    [C:\WINDOWS\System32\Kvsc3.dll]  [N/A, ]
    [C:\WINDOWS\System32\AVPSrv.dll]  [N/A, ]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [C:\WINDOWS\System32\MsIMMs32.dll]  [N/A, ]
    [C:\WINDOWS\System32\NVDispDrv.dll]  [N/A, ]
    [C:\WINDOWS\System32\MsPrint32D.dll]  [N/A, ]
    [C:\WINDOWS\System32\cmdbcs.dll]  [N/A, ]
    [C:\WINDOWS\System32\upxdnd.dll]  [N/A, ]
    [C:\WINDOWS\System32\msccrt.dll]  [N/A, ]
    [C:\WINDOWS\System32\DbgHlp32.dll]  [N/A, ]
gototop
 

[PID: 452 / EADING][C:\WINDOWS\Domino.exe]  [, 3, 6, 818, 7]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
[PID: 548 / EADING][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.18]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 660 / EADING][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 920 / EADING][C:\WINDOWS\System32\k11919153275.exe]  [N/A, ]
[PID: 584 / EADING][C:\Program Files\MSN Messenger\msnmsgr.exe]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\MSNCore.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\msidcrl40.dll]  [Microsoft Corporation, 4.100.313.1]
    [C:\Program Files\MSN Messenger\ContactsUX.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\MSN Messenger\msgslang.8.1.0178.00.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\msgsres.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\MSGSWCAM.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\sirenacm.dll]  [Microsoft Corp., 8.1.0178.00]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\Program Files\MSN Messenger\lmcdata.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\contact.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\MSN Messenger\abssm.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\custsat.dll]  [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[PID: 2216 / EADING][C:\WINDOWS\System32\k11919284575.exe]  [N/A, ]
[PID: 3956 / EADING][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
    [C:\WINDOWS\System32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT