result.txt是这样的,但我不懂操作注册表之类的高级东东。有没有简捷点的工具啊!
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Trojan]
C:\WINDOWS\SYSTEM32\5102A80.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_5102A80
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\5102A80
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_5102A80
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\5102A80
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[nwiuu/dfssvrTrojan Horse]
C:\WINDOWS\SYSTEM32\22D75360.DLL
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[BaiduSearchPartner]
C:\WINDOWS\SYSTEM32\DRIVERS\BDGUARD.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BDGUARD
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[BaiduSuperSoBa]
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\伴侣导航.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\帮助指南.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\广告拦截.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\垃圾清理.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\屏蔽列表.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\系统加速.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\修复功能.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\隐私保护.URL
C:\DOCUMENTS AND SETTINGS\ALL USERS\「开始」菜单\程序\百度工具栏\自定义按钮.URL
C:\DOCUMENTS AND SETTINGS\RAYLINECN\LOCAL SETTINGS\APPLICATION DATA\BAIDU\
C:\PROGRAM FILES\BAIDU\BAR\
C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DAT
C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
C:\PROGRAM FILES\BAIDU\BAR\BANG.INI
C:\PROGRAM FILES\BAIDU\BAR\BDGDINS.DLL
C:\PROGRAM FILES\BAIDU\BAR\LOADMOVIE.SWF
C:\PROGRAM FILES\BAIDU\BAR\LOGEX.DAT
C:\PROGRAM FILES\BAIDU\BAR\MEDIALOG.DAT
C:\PROGRAM FILES\BAIDU\BAR\NAMEDSITES.DAT
C:\WINDOWS\SOSUO.COL
C:\WINDOWS\SYSTEM32\BDGUARD.DAT
C:\WINDOWS\SYSTEM32\BDGUARDS.DAT
C:\WINDOWS\SYSTEM32\IEXP_LOG.TXT
HKEY_CLASSES_ROOT\BAIDUBAR.BAIDU
HKEY_CLASSES_ROOT\BAIDUBAR.BAIDU.1
HKEY_CLASSES_ROOT\BAIDUBAR.TOOL
HKEY_CLASSES_ROOT\BAIDUBAR.TOOL.1
HKEY_CLASSES_ROOT\BAIDUBAREX.BANDIE
HKEY_CLASSES_ROOT\BAIDUBAREX.BANDIE.1
HKEY_CLASSES_ROOT\BAIDUBAREX.BDHOMEPAGE
HKEY_CLASSES_ROOT\BAIDUBAREX.BDHOMEPAGE.1
HKEY_CLASSES_ROOT\BAIDUBAREX.DROPTARGET
HKEY_CLASSES_ROOT\BAIDUBAREX.DROPTARGET.1
HKEY_CLASSES_ROOT\CLSID\{77FEF28E-EB96-44FF-B511-3185DEA48697}
HKEY_CLASSES_ROOT\CLSID\{7C76C055-ED6E-4535-A70F-CD476E727F67}
HKEY_CLASSES_ROOT\CLSID\{A7F05EE4-0426-454F-8013-C41E3596E9E9}
HKEY_CLASSES_ROOT\CLSID\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
HKEY_CLASSES_ROOT\CLSID\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}
HKEY_CLASSES_ROOT\CLSID\{FE14F22E-BE14-4F08-A80F-F27BC3A67B2D}
HKEY_CLASSES_ROOT\INTERFACE\{464C8A26-31E9-411C-9583-5B858E631DCC}
HKEY_CLASSES_ROOT\INTERFACE\{89FDCC4B-8D91-49B0-81A6-18BCFF582735}
HKEY_CLASSES_ROOT\INTERFACE\{96249369-D3DC-4AE6-8A3B-E7109D46E98D}
HKEY_CLASSES_ROOT\INTERFACE\{A294F8EB-86D9-4C4A-8B3E-909253761C64}
HKEY_CLASSES_ROOT\MIMEFILTER.ADFILTER
HKEY_CLASSES_ROOT\MIMEFILTER.ADFILTER.1
HKEY_CLASSES_ROOT\TYPELIB\{6AFC2761-1253-427C-9A56-385B4609BE1D}
HKEY_CURRENT_USER\SOFTWARE\BAIDU\BAIDUBAR
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{77FEF28E-EB96-44FF-B511-3185DEA48697}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
HKEY_LOCAL_MACHINE\SOFTWARE\BAIDU\BAIDUBAR
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIDUBAREX.BANDIE
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIDUBAREX.BANDIE.1
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIDUBAREX.DROPTARGET
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{77FEF28E-EB96-44FF-B511-3185DEA48697}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{7C76C055-ED6E-4535-A70F-CD476E727F67}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{A7F05EE4-0426-454F-8013-C41E3596E9E9}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{FE14F22E-BE14-4F08-A80F-F27BC3A67B2D}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{464C8A26-31E9-411C-9583-5B858E631DCC}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{89FDCC4B-8D91-49B0-81A6-18BCFF582735}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{96249369-D3DC-4AE6-8A3B-E7109D46E98D}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{A294F8EB-86D9-4C4A-8B3E-909253761C64}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{6AFC2761-1253-427C-9A56-385B4609BE1D}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{77FEF28E-EB96-44FF-B511-3185DEA48697}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SOBAR
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_BDGUARD
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\BDGUARD
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET002\ENUM\ROOT\LEGACY_BDGUARD
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET002\SERVICES\BDGUARD
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_BDGUARD
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[3721Keyword]
K:\SETUP\桌面\小程序\IEREPAIRER.EXE
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Trojan.psw.avx]
C:\WINDOWS\SYSTEM32\3D144530.DLL
C:\WINDOWS\SYSTEM32\43ACDCC5.DLL
C:\WINDOWS\SYSTEM32\4BF9CBA3.CFG
C:\WINDOWS\SYSTEM32\4BF9CBA3.DLL
C:\WINDOWS\SYSTEM32\9FD8DB.SYS
C:\WINDOWS\SYSTEM32\D7C79813.DLL
C:\WINDOWS\SYSTEM32\DE02F764.DLL
C:\WINDOWS\SYSTEM32\GDIPRO.DLL
C:\WINDOWS\SYSTEM32\SYS05020.ADD
C:\WINDOWS\SYSTEM32\SYS05020.DLL
HKEY_CLASSES_ROOT\CLSID\{22D75360-199D-4F79-880D-82E766675F06}
HKEY_CLASSES_ROOT\CLSID\{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57}
HKEY_CLASSES_ROOT\CLSID\{D7C79813-9233-4AE0-832C-99B2E8019673}
HKEY_CLASSES_ROOT\CLSID\{E3367679-4775-4244-A62E-4CFE58FC850B}
HKEY_CLASSES_ROOT\CLSID\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{22D75360-199D-4F79-880D-82E766675F06}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{D7C79813-9233-4AE0-832C-99B2E8019673}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{E3367679-4775-4244-A62E-4CFE58FC850B}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{22D75360-199D-4F79-880D-82E766675F06}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{D7C79813-9233-4AE0-832C-99B2E8019673}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{E3367679-4775-4244-A62E-4CFE58FC850B}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_9FD8DB
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\9FD8DB
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET002\SERVICES\9FD8DB
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_9FD8DB
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\9FD8DB
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Trojan.msosiocp.dosjisn]
C:\WINDOWS\SYSTEM32\HBQQXX.DLL
C:\WINDOWS\SYSTEM32\HBWD.DLL
C:\WINDOWS\SYSTEM32\HBWOW.DLL
HKEY_CLASSES_ROOT\CLSID\{4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Trojan.ytewcxzsw.wrew2ds]
C:\WINDOWS\SYSTEM32\122B901E.DLL
C:\WINDOWS\SYSTEM32\4901228.SYS
C:\WINDOWS\SYSTEM32\E3367679.DLL
C:\WINDOWS\SYSTEM32\E4814792.DLL
HKEY_CLASSES_ROOT\CLSID\{3D144530-43DA-47CC-B7C7-A3A9F3B9A6B2}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{3D144530-43DA-47CC-B7C7-A3A9F3B9A6B2}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{3D144530-43DA-47CC-B7C7-A3A9F3B9A6B2}
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_4901228
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\4901228
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_4901228
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\4901228
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Trojan.bndmss.wmel32]
HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\HBKERNEL32
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\HBKERNEL32
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Trojan.upnpsrv]
HKEY_CLASSES_ROOT\CLSID\{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}
HKEY_CLASSES_ROOT\CLSID\{43ACDCC5-9009-4AF4-B80A-93BC656EF298}
HKEY_CLASSES_ROOT\CLSID\{DE02F764-C51A-4788-9597-D78ECC2AC08F}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{43ACDCC5-9009-4AF4-B80A-93BC656EF298}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{DE02F764-C51A-4788-9597-D78ECC2AC08F}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{43ACDCC5-9009-4AF4-B80A-93BC656EF298}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{DE02F764-C51A-4788-9597-D78ECC2AC08F}
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Unknown Trojan Horse/Virus]
C:\WINDOWS\SYSTEM32\12B02216.DLL
C:\WINDOWS\SYSTEM32\9F684DE8.DLL
C:\WINDOWS\SYSTEM32\A8FC611B.DLL
C:\WINDOWS\SYSTEM32\CABA599D.DLL
C:\WINDOWS\SYSTEM32\DLLCACHE\PRINTUI.DLL
HKEY_CLASSES_ROOT\CLSID\{12B02216-AC3F-42A7-8313-449771237061}
HKEY_CLASSES_ROOT\CLSID\{9F684DE8-3E87-4174-9033-E02A3DFD8B61}
HKEY_CLASSES_ROOT\CLSID\{CABA599D-5089-4865-9420-E41FA3C1F55F}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{12B02216-AC3F-42A7-8313-449771237061}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{9F684DE8-3E87-4174-9033-E02A3DFD8B61}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{CABA599D-5089-4865-9420-E41FA3C1F55F}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{12B02216-AC3F-42A7-8313-449771237061}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{9F684DE8-3E87-4174-9033-E02A3DFD8B61}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS\{CABA599D-5089-4865-9420-E41FA3C1F55F}
[2.8.1.8.0815 - 2.8.22.8.1023]
2008-10-25 20:19
[Maybe Useless object]
C:\WINDOWS\SYSTEM32\DRIVERS\HBKERNEL32.SYS