瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

12   1  /  2  页   跳转

[已解决] windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

我的windows server 2003啊……

症状:
IE无法打开新窗口;窗口任务栏最小化无显示,只能用tab键切换;部分安全软件无法运行或损坏;文件无法复制/粘贴;无法显示隐藏文件;输入法图标无法显示;无法上网,网络连接中为空,且不能新建网络连接,部分系统服务无法启动等。

[CODE]
2008-12-03,18:28:16
System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)
Windows Server 2003 Enterprise Edition  (Build 3790) - 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描
    计划任务
    API HOOK
    隐藏进程

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <Windows木马防火墙><F:\Windowsmm\Trojanwall.exe>  [风云谷]
    <RavTray><"C:\Program Files\Rising\Rav\RavTray.exe">  [(Verified)Beijing Rising Information Technology Corporation Limited]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [(Verified)Beijing Rising Information Technology Corporation Limited]
    <360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><%SystemRoot%\system32\logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [Microsoft Corporation]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [Microsoft Corporation]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [Microsoft Corporation]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [Microsoft Corporation]
    <SysTray><C:\WINDOWS\system32\stobject.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [Microsoft Corporation]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}]
    <%IEHARDENADMIN_BASE_DESC%><%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenAdmin>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}]
    <%IEHARDENUSER_DESC%><%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenUser>  [Microsoft Corporation]
==================================
启动文件夹
[服务管理器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\服务管理器.lnk --> C:\PROGRA~1\MICROS~1\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><N>
==================================

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727; InfoPath.2; MAXTHON 2.0)
最后编辑broncpan 最后编辑于 2008-12-03 21:09:07
分享到:
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

==================================
服务
[Alerter / Alerter][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\system32\alrsvc.dll><Microsoft Corporation>
[Application Layer Gateway Service / ALG][Stopped/Manual Start]
  <C:\WINDOWS\System32\alg.exe><Microsoft Corporation>
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><Microsoft Corporation>
[Windows Audio / AudioSrv][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\audiosrv.dll><Microsoft Corporation>
[Background Intelligent Transfer Service / BITS][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\qmgr.dll><Microsoft Corporation>
[Computer Browser / Browser][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\browser.dll><Microsoft Corporation>
[Indexing Service / CiSvc][Stopped/Disabled]
  <C:\WINDOWS\system32\cisvc.exe><Microsoft Corporation>
[ClipBook / ClipSrv][Stopped/Disabled]
  <C:\WINDOWS\system32\clipsrv.exe><Microsoft Corporation>
[COM+ System Application / COMSysApp][Stopped/Manual Start]
  <C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}><Microsoft Corporation>
[Cryptographic Services / CryptSvc][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\cryptsvc.dll><Microsoft Corporation>
[DCOM Server Process Launcher / DcomLaunch][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost -k DcomLaunch-->%SystemRoot%\system32\rpcss.dll><Microsoft Corporation>
[Distributed File System / Dfs][Stopped/Auto Start]
  <C:\WINDOWS\system32\Dfssvc.exe><Microsoft Corporation>
[DHCP Client / Dhcp][Running/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k NetworkService-->%SystemRoot%\System32\dhcpcsvc.dll><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINDOWS\System32\dmadmin.exe /com><Microsoft Corporation>
[Logical Disk Manager / dmserver][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\dmserver.dll><Microsoft Corporation>
[DNS Client / Dnscache][Running/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k NetworkService-->%SystemRoot%\System32\dnsrslvr.dll><Microsoft Corporation>
[Error Reporting Service / ERSvc][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k WinErr-->%SystemRoot%\System32\ersvc.dll><Microsoft Corporation>
[Event Log / Eventlog][Running/Auto Start]
  <C:\WINDOWS\system32\services.exe><Microsoft Corporation>
[COM+ Event System / EventSystem][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\es.dll><Microsoft Corporation>
[Help and Support / helpsvc][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[HTTP SSL / HTTPFilter][Stopped/Manual Start]
  <C:\WINDOWS\system32\lsass.exe-->%SystemRoot%\System32\w3ssl.dll><Microsoft Corporation>
[IIS Admin Service / IISADMIN][Stopped/Auto Start]
  <C:\WINDOWS\system32\inetsrv\inetinfo.exe><Microsoft Corporation>
[IMAPI CD-Burning COM Service / ImapiService][Stopped/Disabled]
  <C:\WINDOWS\system32\imapi.exe><Microsoft Corporation>
[Intersite Messaging / IsmServ][Stopped/Disabled]
  <C:\WINDOWS\System32\ismserv.exe><Microsoft Corporation>
[Kerberos Key Distribution Center / kdc][Stopped/Disabled]
  <C:\WINDOWS\System32\lsass.exe><Microsoft Corporation>
[Server / lanmanserver][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\srvsvc.dll><Microsoft Corporation>
[Workstation / lanmanworkstation][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wkssvc.dll><Microsoft Corporation>
[License Logging / LicenseService][Stopped/Disabled]
  <C:\WINDOWS\System32\llssrv.exe><Microsoft Corporation>
[TCP/IP NetBIOS Helper / LmHosts][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32\lmhsvc.dll><Microsoft Corporation>
[Messenger / Messenger][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\msgsvc.dll><Microsoft Corporation>
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Disabled]
  <C:\WINDOWS\system32\mnmsrvc.exe><Microsoft Corporation>
[Distributed Transaction Coordinator / MSDTC][Stopped/Auto Start]
  <C:\WINDOWS\system32\msdtc.exe><Microsoft Corporation>
[Windows Installer / MSIServer][Stopped/Manual Start]
  <C:\WINDOWS\system32\msiexec.exe /V><Microsoft Corporation>
[Microsoft Search / MSSEARCH][Stopped/Auto Start]
  <"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"><Microsoft Corporation>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
  <g:\教师信~1\tis\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
  <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[Network DDE / NetDDE][Stopped/Disabled]
  <C:\WINDOWS\system32\netdde.exe><Microsoft Corporation>
[Network DDE DSDM / NetDDEdsdm][Stopped/Disabled]
  <C:\WINDOWS\system32\netdde.exe><Microsoft Corporation>
[Net Logon / Netlogon][Stopped/Manual Start]
  <C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[Network Connections / Netman][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\netman.dll><Microsoft Corporation>
[Network Location Awareness (NLA) / Nla][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mswsock.dll><Microsoft Corporation>
[File Replication / NtFrs][Stopped/Manual Start]
  <C:\WINDOWS\system32\ntfrs.exe><Microsoft Corporation>
[NT LM Security Support Provider / NtLmSsp][Running/Manual Start]
  <C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[Removable Storage / NtmsSvc][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\ntmssvc.dll><Microsoft Corporation>
[Plug and Play / PlugPlay][Running/Auto Start]
  <C:\WINDOWS\system32\services.exe><Microsoft Corporation>
[IPSEC Services / PolicyAgent][Stopped/Auto Start]
  <C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[Protected Storage / ProtectedStorage][Running/Auto Start]
  <C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[Remote Access Auto Connection Manager / RasAuto][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasauto.dll><Microsoft Corporation>
[Remote Access Connection Manager / RasMan][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasmans.dll><Microsoft Corporation>
[RavService / RavService][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\RavService.exe"><Beijing Rising Information Technology Co., Ltd.>
[Remote Desktop Help Session Manager / RDSessMgr][Stopped/Manual Start]
  <C:\WINDOWS\system32\sessmgr.exe><Microsoft Corporation>
[Routing and Remote Access / RemoteAccess][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mprdim.dll><Microsoft Corporation>
[Remote Registry / RemoteRegistry][Running/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k regsvc-->%SystemRoot%\system32\regsvc.dll><Microsoft Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator][Stopped/Manual Start]
  <C:\WINDOWS\system32\locator.exe><Microsoft Corporation>
[Remote Procedure Call (RPC) / RpcSs][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Information Technology Co., Ltd.>
[Resultant Set of Policy Provider / RSoPProv][Stopped/Manual Start]
  <C:\WINDOWS\system32\RSoPProv.exe><Microsoft Corporation>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
  <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Information Technology Co., Ltd.>
[Special Administration Console Helper / sacsvr][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\system32\sacsvr.dll><Microsoft Corporation>
[Security Accounts Manager / SamSs][Running/Auto Start]
  <C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[Smart Card / SCardSvr][Stopped/Manual Start]
  <C:\WINDOWS\System32\SCardSvr.exe><Microsoft Corporation>
[Task Scheduler / Schedule][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\system32\schedsvc.dll><Microsoft Corporation>
[Secondary Logon / seclogon][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\seclogon.dll><Microsoft Corporation>
[System Event Notification / SENS][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\sens.dll><Microsoft Corporation>
[Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) / SharedAccess][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\ipnathlp.dll><Microsoft Corporation>
[Shell Hardware Detection / ShellHWDetection][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\shsvcs.dll><Microsoft Corporation>
[Print Spooler / Spooler][Running/Auto Start]
  <C:\WINDOWS\system32\spoolsv.exe><Microsoft Corporation>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
  <g:\教师信~1\tis\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Windows Image Acquisition (WIA) / stisvc][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k imgsvc-->%SystemRoot%\system32\wiaservc.dll><Microsoft Corporation>
[Microsoft Software Shadow Copy Provider / swprv][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k swprv-->%Systemroot%\System32\swprv.dll><Microsoft Corporation>
[Performance Logs and Alerts / SysmonLog][Stopped/Manual Start]
  <C:\WINDOWS\system32\smlogsvc.exe><Microsoft Corporation>
[Telephony / TapiSrv][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k tapisrv-->%SystemRoot%\System32\tapisrv.dll><Microsoft Corporation>
[Terminal Services / TermService][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k termsvcs-->%SystemRoot%\System32\termsrv.dll><Microsoft Corporation>
[Themes / Themes][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\shsvcs.dll><Microsoft Corporation>
[Telnet / TlntSvr][Stopped/Disabled]
  <C:\WINDOWS\system32\tlntsvr.exe><Microsoft Corporation>
[Distributed Link Tracking Server / TrkSvr][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\trksvr.dll><Microsoft Corporation>
[Distributed Link Tracking Client / TrkWks][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\trkwks.dll><Microsoft Corporation>
[Terminal Services Session Directory / Tssdis][Stopped/Disabled]
  <C:\WINDOWS\System32\tssdis.exe><Microsoft Corporation>
[Upload Manager / uploadmgr][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><Microsoft Corporation>
[Uninterruptible Power Supply / UPS][Stopped/Manual Start]
  <C:\WINDOWS\System32\ups.exe><Microsoft Corporation>
[Virtual Disk Service / vds][Stopped/Manual Start]
  <C:\WINDOWS\System32\vds.exe><Microsoft Corporation>
[Volume Shadow Copy / VSS][Stopped/Manual Start]
  <C:\WINDOWS\System32\vssvc.exe><Microsoft Corporation>
[Windows Time / W32Time][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\w32time.dll><Microsoft Corporation>
[World Wide Web Publishing Service / W3SVC][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k iissvcs-->C:\WINDOWS\system32\inetsrv\iisw3adm.dll><Microsoft Corporation>
[WebClient / WebClient][Stopped/Disabled]
  <C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32\webclnt.dll><Microsoft Corporation>
[WinHTTP Web Proxy Auto-Discovery Service / WinHttpAutoProxySvc][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k LocalService-->winhttp.dll><Microsoft Corporation>
[Windows Management Instrumentation / winmgmt][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\wbem\WMIsvc.dll><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\mspmsnsv.dll><Microsoft Corporation>
[Windows Management Instrumentation Driver Extensions / Wmi][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\advapi32.dll><Microsoft Corporation>
[WMI Performance Adapter / WmiApSrv][Stopped/Manual Start]
  <C:\WINDOWS\system32\wbem\wmiapsrv.exe><Microsoft Corporation>
[Automatic Updates / wuauserv][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\wuauserv.dll><Microsoft Corporation>
[Wireless Configuration / WZCSVC][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wzcsvc.dll><Microsoft Corporation>

==================================
驱动程序
[360AntiArp / 360AntiArp][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
[Microsoft ACPI Driver / ACPI][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\ACPI.sys><Microsoft Corporation>
[AFD 网络支持环境 / AFD][Running/Auto Start]
  <\SystemRoot\System32\drivers\afd.sys><Microsoft Corporation>
[aliimz / aliimz][Stopped/Manual Start]
  <System32\Drivers\aliimz.sys><N/A>
[RAS Asynchronous Media Driver / AsyncMac][Stopped/Manual Start]
  <system32\DRIVERS\asyncmac.sys><Microsoft Corporation>
[标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\atapi.sys><Microsoft Corporation>
[ati2mpad / ati2mpad][Running/Manual Start]
  <system32\DRIVERS\ati2mpad.sys><ATI Technologies Inc.>
[ATM ARP Client Protocol / Atmarpc][Stopped/Manual Start]
  <system32\DRIVERS\atmarpc.sys><Microsoft Corporation>
[音频存根驱动程序 / audstub][Running/Manual Start]
  <system32\DRIVERS\audstub.sys><Microsoft Corporation>
[CD-ROM Driver / Cdrom][Running/System Start]
  <system32\DRIVERS\cdrom.sys><Microsoft Corporation>
[群集磁盘驱动程序 / ClusDisk][Stopped/Disabled]
  <system32\DRIVERS\ClusDisk.sys><Microsoft Corporation>
[CRC 磁盘筛选驱动程序 / crcdisk][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\crcdisk.sys><Microsoft Corporation>
[DfsDriver / DfsDriver][Running/Boot Start]
  <\SystemRoot\system32\drivers\Dfs.sys><Microsoft Corporation>
[磁盘驱动程序 / Disk][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\disk.sys><Microsoft Corporation>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><Microsoft Corporation>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><Microsoft Corporation>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys><Microsoft Corporation>
[Intel(R) PRO/1000 Device Driver / E1000][Stopped/Manual Start]
  <system32\DRIVERS\e1000325.sys><Intel Corporation>
[Floppy Disk Controller Driver / Fdc][Running/Manual Start]
  <system32\DRIVERS\fdc.sys><Microsoft Corporation>
[软盘驱动程序 / Flpydisk][Running/Manual Start]
  <system32\DRIVERS\flpydisk.sys><Microsoft Corporation>
[FsVga / FsVga][Running/System Start]
  <system32\DRIVERS\fsvga.sys><Microsoft Corporation>
[Volume Manager Driver / Ftdisk][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\ftdisk.sys><Microsoft Corporation>
[Generic Packet Classifier / Gpc][Running/Manual Start]
  <system32\DRIVERS\msgpc.sys><Microsoft Corporation>
[HBKernel32 Driver / HBKernel32][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\HBKernel32.sys><N/A>
[HookCont / HookCont][Running/System Start]
  <\SystemRoot\system32\drivers\HookCont.sys><Beijing Rising Information Technology Co., Ltd.>
[HookNtos / HookNtos][Running/System Start]
  <\SystemRoot\system32\drivers\HookNtos.sys><Beijing Rising Information Technology Co., Ltd.>
[HookReg / HookReg][Running/System Start]
  <\SystemRoot\system32\drivers\HookReg.sys><Beijing Rising Information Technology Co., Ltd.>
[HookSys / HookSys][Running/System Start]
  <\SystemRoot\system32\drivers\HookSys.sys><Beijing Rising Information Technology Co., Ltd.>
[HTTP / HTTP][Running/Manual Start]
  <System32\Drivers\HTTP.sys><Microsoft Corporation>
[i8042 Keyboard and PS/2 Mouse Port Driver / i8042prt][Running/System Start]
  <system32\DRIVERS\i8042prt.sys><Microsoft Corporation>
[CD-Burning Filter Driver / imapi][Stopped/System Start]
  <system32\DRIVERS\imapi.sys><Microsoft Corporation>
[IntelIde / IntelIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\intelide.sys><Microsoft Corporation>
[IP Traffic Filter Driver / IpFilterDriver][Stopped/Manual Start]
  <system32\DRIVERS\ipfltdrv.sys><Microsoft Corporation>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <system32\DRIVERS\ipinip.sys><N/A>
[IP Network Address Translator / IpNat][Stopped/Manual Start]
  <system32\DRIVERS\ipnat.sys><Microsoft Corporation>
[IPSEC driver / IPSec][Running/System Start]
  <system32\DRIVERS\ipsec.sys><Microsoft Corporation>
[PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\isapnp.sys><Microsoft Corporation>
[Keyboard Class Driver / Kbdclass][Running/System Start]
  <system32\DRIVERS\kbdclass.sys><Microsoft Corporation>
[Mouse Class Driver / Mouclass][Running/System Start]
  <system32\DRIVERS\mouclass.sys><Microsoft Corporation>
[mraid35x / mraid35x][Running/Boot Start]
  <\SystemRoot\system32\drivers\mraid35x.sys><LSI Logic Corporation>
[WebDav Client Redirector / MRxDAV][Stopped/Manual Start]
  <system32\DRIVERS\mrxdav.sys><Microsoft Corporation>
[MRxSmb / MRxSmb][Running/System Start]
  <system32\DRIVERS\mrxsmb.sys><Microsoft Corporation>
[Remote Access NDIS TAPI Driver / NdisTapi][Running/Manual Start]
  <system32\DRIVERS\ndistapi.sys><Microsoft Corporation>
[NDIS 用户模式 I/O 协议 / Ndisuio][Running/Manual Start]
  <system32\DRIVERS\ndisuio.sys><Microsoft Corporation>
[Remote Access NDIS WAN Driver / NdisWan][Running/Manual Start]
  <system32\DRIVERS\ndiswan.sys><Microsoft Corporation>
[NetBIOS Interface / NetBIOS][Running/System Start]
  <system32\DRIVERS\netbios.sys><Microsoft Corporation>
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

[NetBios over Tcpip / NetBT][Running/System Start]
  <system32\DRIVERS\netbt.sys><Microsoft Corporation>
[Parallel port driver / Parport][Running/Manual Start]
  <system32\DRIVERS\parport.sys><Microsoft Corporation>
[Parvdm / Parvdm][Running/Auto Start]
  <system32\DRIVERS\parvdm.sys><Microsoft Corporation>
[PCI Bus Driver / PCI][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\pci.sys><Microsoft Corporation>
[WAN Miniport (PPTP) / PptpMiniport][Running/Manual Start]
  <system32\DRIVERS\raspptp.sys><Microsoft Corporation>
[处理器驱动程序 / Processor][Running/Manual Start]
  <system32\DRIVERS\processr.sys><Microsoft Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Remote Access Auto Connection Driver / RasAcd][Running/System Start]
  <system32\DRIVERS\rasacd.sys><Microsoft Corporation>
[WAN Miniport (L2TP) / Rasl2tp][Running/Manual Start]
  <system32\DRIVERS\rasl2tp.sys><Microsoft Corporation>
[远程访问 PPPOE 驱动程序 / RasPppoe][Running/Manual Start]
  <system32\DRIVERS\raspppoe.sys><Microsoft Corporation>
[Direct Parallel / Raspti][Running/Manual Start]
  <system32\DRIVERS\raspti.sys><Microsoft Corporation>
[Rdbss / Rdbss][Running/System Start]
  <system32\DRIVERS\rdbss.sys><Microsoft Corporation>
[RDPCDD / RDPCDD][Running/System Start]
  <System32\DRIVERS\RDPCDD.sys><Microsoft Corporation>
[Terminal Server Device Redirector Driver / rdpdr][Running/Manual Start]
  <system32\DRIVERS\rdpdr.sys><Microsoft Corporation>
[Digital CD Audio Playback Filter Driver / redbook][Running/System Start]
  <system32\DRIVERS\redbook.sys><Microsoft Corporation>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Information Technology Co., Ltd.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Serenum Filter Driver / serenum][Running/Manual Start]
  <system32\DRIVERS\serenum.sys><Microsoft Corporation>
[Serial port driver / Serial][Running/System Start]
  <system32\DRIVERS\serial.sys><Microsoft Corporation>
[Srv / Srv][Stopped/Manual Start]
  <system32\DRIVERS\srv.sys><Microsoft Corporation>
[Software Bus Driver / swenum][Running/Manual Start]
  <system32\DRIVERS\swenum.sys><Microsoft Corporation>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[终端设备驱动程序 / TermDD][Running/System Start]
  <system32\DRIVERS\termdd.sys><Microsoft Corporation>
[Microcode Update Driver / Update][Running/Manual Start]
  <system32\DRIVERS\update.sys><Microsoft Corporation>
[USB2 Enabled Hub / usbhub][Running/Manual Start]
  <system32\DRIVERS\usbhub.sys><Microsoft Corporation>
[USB 大容量存储驱动程序 / USBSTOR][Running/Manual Start]
  <system32\DRIVERS\USBSTOR.SYS><Microsoft Corporation>
[Microsoft USB Universal Host Controller Miniport Driver / usbuhci][Running/Manual Start]
  <system32\DRIVERS\usbuhci.sys><Microsoft Corporation>
[VGA 显示控制器。 / VgaSave][Running/System Start]
  <\SystemRoot\System32\drivers\vga.sys><Microsoft Corporation>
[存储卷 / VolSnap][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\volsnap.sys><Microsoft Corporation>
[Remote Access IP ARP Driver / Wanarp][Running/Manual Start]
  <system32\DRIVERS\wanarp.sys><Microsoft Corporation>
[网络负载平衡 / WLBS][Stopped/Manual Start]
  <system32\DRIVERS\wlbs.sys><Microsoft Corporation>
[KernelCheck / KernelCheck][Running/Manual Start]
  <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vhjp\KpCheck.sys><N/A>

==================================
浏览器加载项
[]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <, >
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, (Signed) 360.CN>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, >
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
[360SafeLive]
  {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, (Signed) 360.cn>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>

==================================
正在运行的进程
[PID: 336][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 400][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CSRSRV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\basesrv.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\winsrv.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\KERNEL32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\sxs.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 424][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NDdeApi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSTA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\PROFMAP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\REGAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\PSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSGINA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHSVCS.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\sfc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINTRUST.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\imagehlp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\Comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSCARD.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WTSAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sxs.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\shell32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\wldap32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\cscdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WlNotify.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPR.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\COMCTL32.dll]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SAMLIB.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\cscui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NTMARTA.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\CLBCatQ.DLL]  [Microsoft Corporation, 2001.12.4720.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wbem\wbemprox.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wbem\wbemcomn.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 468][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SCESRV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\AUTHZ.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\umpnpmgr.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSTA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NCObjAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSVCP60.dll]  [Microsoft Corporation, 6.05.2144.0]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\eventlog.dll]  [Microsoft Corporation, 5.2.3790.121 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\PSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wtsapi32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 480][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\LSASRV.dll]  [Microsoft Corporation, 5.2.3790.134 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\SAMSRV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\cryptdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SAMLIB.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPR.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msprivs.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kerberos.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msv1_0.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\netlogon.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\w32time.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSVCP60.dll]  [Microsoft Corporation, 6.05.2144.0]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\AUTHZ.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\schannel.dll]  [Microsoft Corporation, 5.2.3790.132 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wdigest.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\PSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\setupapi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RASSFM.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\KDCSVC.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NTDSA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NTDSATQ.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSWSOCK.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ESENT.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\scecli.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ipsecsvc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\oakley.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINIPSEC.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\pstorsvc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\psbase.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 708][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.33]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

[C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
[PID: 752][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [c:\windows\system32\dhcpcsvc.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [c:\windows\system32\DNSAPI.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [c:\windows\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [c:\windows\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [c:\windows\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [c:\windows\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [c:\windows\system32\dnsrslvr.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\netman.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPRAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ACTIVEDS.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\adsldpc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\credui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\ATL.DLL]  [Microsoft Corporation, 3.05.2283]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\rtutils.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SAMLIB.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RASAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rasman.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\TAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\WZCSvc.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WMI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WTSAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSTA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ESENT.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WZCSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 812][C:\PROGRAM FILES\RISING\RAV\ravmond.exe]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.80]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\PROGRAM FILES\RISING\RAV\BWList.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.5]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\WSOCK32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.1]
    [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.19]
    [C:\PROGRAM FILES\RISING\RAV\RsLog.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.36]
    [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\PROGRAM FILES\RISING\RAV\MonRule.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.10]
    [C:\PROGRAM FILES\RISING\RAV\Hooksys.dll]  [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12]
    [C:\PROGRAM FILES\RISING\RAV\HookReg.dll]  [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6]
    [C:\PROGRAM FILES\RISING\RAV\HookNtos.dll]  [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5]
    [C:\PROGRAM FILES\RISING\RAV\rswalmon.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24]
    [C:\PROGRAM FILES\RISING\RAV\recomp.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41]
    [C:\PROGRAM FILES\RISING\RAV\refs.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18]
    [C:\PROGRAM FILES\RISING\RAV\ffr.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
    [C:\WINDOWS\system32\sfc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINTRUST.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\imagehlp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.9]
    [C:\PROGRAM FILES\RISING\RAV\HookCont.dll]  [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3]
    [C:\Program Files\Rising\Rav\fakescan.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.14]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.39]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\PROGRAM FILES\RISING\RAV\viruslib.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27]
    [C:\PROGRAM FILES\RISING\RAV\relibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
    [C:\WINDOWS\system32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.3]
    [C:\PROGRAM FILES\RISING\RAV\extfile.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32]
    [C:\PROGRAM FILES\RISING\RAV\pearc.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8]
    [C:\WINDOWS\system32\netapi32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\PROGRAM FILES\RISING\RAV\nvfile.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7]
    [C:\PROGRAM FILES\RISING\RAV\scanexec.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22]
    [C:\PROGRAM FILES\RISING\RAV\unexe.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6]
    [C:\PROGRAM FILES\RISING\RAV\scanex.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 1, 0]
    [C:\PROGRAM FILES\RISING\RAV\scanpack.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10]
    [C:\PROGRAM FILES\RISING\RAV\revm.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11]
    [C:\PROGRAM FILES\RISING\RAV\urutils.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7]
    [C:\PROGRAM FILES\RISING\RAV\ur000.dat]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 22]
    [C:\PROGRAM FILES\RISING\RAV\scriptci.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4]
    [C:\PROGRAM FILES\RISING\RAV\uroutine.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27]
    [C:\PROGRAM FILES\RISING\RAV\ur001.dat]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
    [C:\PROGRAM FILES\RISING\RAV\extmail.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10]
    [C:\PROGRAM FILES\RISING\RAV\scansct.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11]
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

[PID: 852][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SPOOLSS.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\localspl.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINTRUST.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\imagehlp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\winspool.drv]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\cnbjmon.dll]  [Microsoft Corporation, 5.2.3680.0 (Lab03_dev(skatari).020509-1043)]
    [C:\WINDOWS\system32\pjlmon.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\tcpmon.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\mgmtapi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\snmpapi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wsnmp32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\usbmon.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\winrnr.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\wshqos.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\win32spl.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETRAP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\inetpp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\icmp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1228][g:\教师信~1\tis\MSSQL\binn\sqlservr.exe]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\ADVAPI32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\USER32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [g:\教师信~1\tis\MSSQL\binn\OPENDS60.DLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\MSVCRT.DLL]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [g:\教师信~1\tis\MSSQL\binn\UMS.DLL]  [Microsoft Corporation, 2000.080.0194.00]
    [g:\教师信~1\tis\MSSQL\binn\SQLSORT.DLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\MSVCIRT.DLL]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ShimEng.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\AppPatch\AcSpecfc.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\DDRAW.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\DCIMAN32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPR.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\PSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\COMCTL32.dll]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [g:\教师信~1\tis\MSSQL\binn\Resources\2052\sqlevn70.RLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\NETAPI32.DLL]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\wmi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\XOLEHLP.DLL]  [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSDTCPRX.dll]  [Microsoft Corporation, 2001.12.4720.480 (srv03_gdr.060207-1522)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\MSVCP60.dll]  [Microsoft Corporation, 6.05.2144.0]
    [C:\WINDOWS\system32\MTXCLU.DLL]  [Microsoft Corporation, 2001.12.4720.480 (srv03_gdr.060207-1522)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WSOCK32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CLUSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RESUTILS.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MFC42u.DLL]  [Microsoft Corporation, 6.05.3014.0]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\System32\winrnr.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [g:\教师信~1\tis\MSSQL\binn\SSNETLIB.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [g:\教师信~1\tis\MSSQL\binn\SSNMPN70.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\security.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\crypt32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [g:\教师信~1\tis\MSSQL\binn\SSmsLPCn.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\ntdsapi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1224][C:\PROGRAM FILES\RISING\RAV\RavStub.exe]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.10]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\COMCTL32.dll]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1288][C:\Program Files\Rising\Rav\RavService.exe]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 77]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\MFC42.DLL]  [Microsoft Corporation, 6.05.3014.0]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\MSVCP60.dll]  [Microsoft Corporation, 6.05.2144.0]
    [C:\WINDOWS\system32\WSOCK32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\DLCenter.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.11]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\snmpapi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

[Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\security.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SECUR32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\inetmib1.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\COMCTL32.DLL]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\WINDOWS\system32\ODBC32.dll]  [Microsoft Corporation, 3.525.1022.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\odbcint.dll]  [Microsoft Corporation, 3.525.1022.0 ((Webdata).030220-1508)]
    [C:\WINDOWS\system32\odbcjt32.dll]  [Microsoft Corporation, 4.0.6205.0]
    [C:\WINDOWS\system32\msjet40.dll]  [Microsoft Corporation, 4.00.6807.0]
    [C:\WINDOWS\system32\mswstr10.dll]  [Microsoft Corporation, 4.00.6508.0]
    [C:\WINDOWS\system32\odbcji32.dll]  [Microsoft Corporation, 4.0.6205.0]
    [C:\WINDOWS\system32\msjter40.dll]  [Microsoft Corporation, 4.00.6508.0]
    [C:\WINDOWS\system32\MSJINT40.DLL]  [Microsoft Corporation, 4.00.6508.0]
    [C:\WINDOWS\system32\odbccp32.dll]  [Microsoft Corporation, 3.525.1022.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msrd3x40.dll]  [Microsoft Corporation, 4.00.6508.0]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\System32\winrnr.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPRAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ACTIVEDS.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\adsldpc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\credui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ATL.DLL]  [Microsoft Corporation, 3.05.2283]
    [C:\WINDOWS\system32\rtutils.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SAMLIB.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CLBCatQ.DLL]  [Microsoft Corporation, 2001.12.4720.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msjtes40.dll]  [Microsoft Corporation, 4.00.6807.0]
    [C:\WINDOWS\system32\VBAJET32.DLL]  [Microsoft Corporation, 6.1.9431]
    [C:\WINDOWS\system32\expsrv.dll]  [Microsoft Corporation, 6.0.9589]
[PID: 1320][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [c:\windows\system32\regsvc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1740][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\BROWSEUI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\SHDOCVW.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CLBCatQ.DLL]  [Microsoft Corporation, 2001.12.4720.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\cscui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\CSCDLL.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\themeui.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSIMG32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msutb.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LINKINFO.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntshrui.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.3790.588 (srv03_gdr.060901-0059)]
    [C:\WINDOWS\system32\WINSTA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\webcheck.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WSOCK32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\stobject.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\BatMeter.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\POWRPROF.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WTSAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETSHELL.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\credui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\CLUSAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.18]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\printui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ACTIVEDS.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\adsldpc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ATL.DLL]  [Microsoft Corporation, 3.05.2283]
    [C:\WINDOWS\system32\CFGMGR32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPR.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MLANG.DLL]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\drprov.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\ntlanman.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\NETUI0.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\NETUI1.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\SAMLIB.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\davclnt.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\browselc.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RASDLG.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPRAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rtutils.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RASAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rasman.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\TAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\COMCTL32.DLL]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\usbui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\diskcopy.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
    [C:\WINDOWS\system32\shdoclc.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\zipfldr.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
[PID: 1876][F:\Windowsmm\Trojanwall.exe]  [风云谷, 5.5.0.1916]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\user32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\advapi32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\oleaut32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\version.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\comctl32.dll]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\shell32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\wininet.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\URLMON.DLL]  [Microsoft Corporation, 6.00.3790.588 (srv03_gdr.060901-0059)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\winmm.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IPHLPAPI.DLL]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [F:\Windowsmm\ftcapi.dll]  [fygsoft, 1.1.0.0]
    [C:\WINDOWS\system32\hhctrl.ocx]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\mui\0804\hhctrlui.dll]  [Microsoft Corporation, 4.74.9429]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wsock32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSWSOCK.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [F:\Windowsmm\PSAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1884][C:\Program Files\Rising\Rav\RavTray.exe]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 37]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\Program Files\Rising\Rav\RavUILib.dll]  [, 18, 0, 0, 1]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\MFC42.DLL]  [Microsoft Corporation, 6.05.3014.0]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\COMCTL32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.3790.588 (srv03_gdr.060901-0059)]
    [C:\WINDOWS\system32\MSVCP60.dll]  [Microsoft Corporation, 6.05.2144.0]
    [C:\WINDOWS\system32\WSOCK32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MPR.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\snmpapi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

[C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\inetmib1.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\Program Files\Rising\Rav\RavTray936.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 37]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\WINDOWS\system32\RICHED32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1900][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.24]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\COMCTL32.dll]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.1]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.19]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1912][C:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Information Technology Co., Ltd., 20.0.01.24]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\COMCTL32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
    [C:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 41]
    [C:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18]
    [C:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27]
    [C:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17]
    [C:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.1]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.19]
    [C:\Program Files\Rising\Rav\MonRule.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.0.10]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
    [C:\WINDOWS\system32\wtsapi32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSTA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\Rsguilib.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\perfproc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1976][C:\Program Files\360safe\safemon\360Tray.exe]  [奇虎网, 5, 0, 0, 1002]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\MFC42.DLL]  [Microsoft Corporation, 6.05.3014.0]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\COMCTL32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.3790.588 (srv03_gdr.060901-0059)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\RICHED32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [C:\WINDOWS\system32\PSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 4, 3, 0, 1003]
    [C:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 4, 2, 0, 1001]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\360safe\live.dll]  [360.cn, 1, 0, 1, 1029]
    [C:\WINDOWS\system32\WINTRUST.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\imagehlp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RASAPI32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rasman.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\TAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rtutils.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\mlang.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wsock32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1988][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSUTB.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
[PID: 220][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\MSVCRT.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\COMCTL32.dll]  [Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\W95SCM.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\ODBC32.dll]  [Microsoft Corporation, 3.525.1022.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SQLUNIRL.dll]  [Microsoft Corporation, 2000.080.0728.00]
    [C:\WINDOWS\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLSVC.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\odbcbcp.dll]  [Microsoft Corporation, 2000.085.1022.00 (srv03_rtm.030324-2048)]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLRESLD.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\odbcint.dll]  [Microsoft Corporation, 3.525.1022.0 ((Webdata).030220-1508)]
    [C:\WINDOWS\system32\clusapi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\resutils.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MFC42u.DLL]  [Microsoft Corporation, 6.05.3014.0]
    [C:\WINDOWS\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\NDDEAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\SQLSVC.RLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\sqlmangr.RLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

[C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 788][C:\WINDOWS\system32\NOTEPAD.EXE]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\COMCTL32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1328][C:\WINDOWS\system32\NOTEPAD.EXE]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\COMCTL32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\OLEAUT32.DLL]  [Microsoft Corporation, 5.2.3790.0]
[PID: 536][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\COMCTL32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VDMDBG.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINSTA.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\WTSAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 584][I:\楼上服务器\Wsyscheck\Wsyscheck\Wsyscheck.exe]  [Wang6071@sina.com.cn, 1.68.32.0]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\advapi32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_5.82.0.0_x-ww_8A69BA05\comctl32.dll]
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

[Microsoft Corporation, 5.82 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\mpr.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\oleaut32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\version.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\winspool.drv]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wsock32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\comctl32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\wintrust.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\imagehlp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CLBCatQ.DLL]  [Microsoft Corporation, 2001.12.4720.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\cscui.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\CSCDLL.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sfc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 284][I:\楼上服务器\sreng\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\user32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
[PID: 368][I:\楼上服务器\sreng\SREb8e2171b.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.2.3790.566 (srv03_gdr.060725-0055)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.2.3790.462 (srv03_gdr.051230-1534)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.2.3790.137 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.100.0_x-ww_8417450B\COMCTL32.dll]  [Microsoft Corporation, 6.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\oledlg.dll]  [Microsoft Corporation, 1.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.2.3790.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.2.3790.0]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.2.3790.139 (srv03_gdr.040116-1702)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.3790.550 (srv03_gdr.060623-0256)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0421.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RICHED20.DLL]  [Microsoft Corporation, 5.31.23.1218]
    [C:\WINDOWS\system32\NTMARTA.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SAMLIB.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\apphelp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Msimtf.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sfc.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\WINTRUST.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\imagehlp.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [I:\楼上服务器\sreng\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\wsock32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\RASAPI32.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rasman.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.2.3790.559 (srv03_gdr.060713-0013)]
    [C:\WINDOWS\system32\TAPI32.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\rtutils.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.3790.588 (srv03_gdr.060901-0059)]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.2.3790.558 (srv03_gdr.060711-0046)]
    [C:\WINDOWS\system32\PSAPI.DLL]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\CLBCatQ.DLL]  [Microsoft Corporation, 2001.12.4720.374 (srv03_gdr.050720-1553)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\LINKINFO.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\ntshrui.dll]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\Winsta.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\utildll.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\cryptnet.dll]  [Microsoft Corporation, 5.131.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\SensApi.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.WinHTTP_6595b64144ccf1df_5.1.0.0_x-ww_E0651936\WINHTTP.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\System32\wshqos.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.2.3790.536 (srv03_gdr.060518-1522)]
    [C:\WINDOWS\system32\wshtcpip.dll]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
gototop
 

回复:windows server 2003 中毒;无法复制粘贴,任务栏无法显示窗口等

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [RAW/IP]
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
RSVP UDP Service Provider
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
RSVP TCP Service Provider
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E6D3206F-48B7-489C-B855-B03092C2A426}] SEQPACKET 0
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E6D3206F-48B7-489C-B855-B03092C2A426}] DATAGRAM 0
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E19C0201-B3D6-473B-999F-A9B09CACF634}] SEQPACKET 1
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E19C0201-B3D6-473B-999F-A9B09CACF634}] DATAGRAM 1
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EF90B4F2-BA26-4228-8803-53A643D62EF8}] SEQPACKET 2
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EF90B4F2-BA26-4228-8803-53A643D62EF8}] DATAGRAM 2
    C:\WINDOWS\system32\mswsock.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      v.onondown.com.cn
127.0.0.2      ymsdasdw1.cn
127.0.0.3      h96b.info
127.0.0.0      xxx.zttwp.cn
127.0.0.0      www.hackerbf.cn
127.0.0.0      geekbyfeng.cn
127.0.0.0      ppp.etimes888.com
127.0.0.0      www.bypk.com
127.0.0.0      CSC3-2004-crl.verisign.com
127.0.0.1      va9sdhun23.cn
127.0.0.0      udp.hjob123.com
127.0.0.2      bnasnd83nd.cn
127.0.0.0      www.gamehacker.com.cn
127.0.0.0      gamehacker.com.cn
127.0.0.3      adlaji.cn
127.0.0.1      858656.com
127.1.1.1      bnasnd83nd.cn
127.0.0.1      my123.com
127.0.0.0      user1.12-27.net
127.0.0.1      8749.com
127.0.0.0      fengent.cn
127.0.0.1      4199.com
127.0.0.1      user1.16-22.net
127.0.0.1      7379.com
127.0.0.1      2be37c5f.3f6e2cc5f0b.com
127.0.0.1      7255.com
127.0.0.1      user1.23-12.net
127.0.0.1      3448.com
127.0.0.1      www.guccia.net
127.0.0.1      7939.com
127.0.0.1      a.o1o1o1.nEt
127.0.0.1      8009.com
127.0.0.1      user1.12-73.cn
127.0.0.1      piaoxue.com
127.0.0.1      3n8nlasd.cn
127.0.0.1      kzdh.com
127.0.0.0      www.sony888.cn
127.0.0.1      about.blank.la
127.0.0.0      user1.asp-33.cn
127.0.0.1      6781.com
127.0.0.0      www.netkwek.cn
127.0.0.1      7322.com
127.0.0.0      ymsdkad6.cn
127.0.0.1      localhost
127.0.0.0      www.lkwueir.cn
127.0.0.1      06.jacai.com
127.0.1.1      user1.23-17.net
127.0.0.1      1.jopenkk.com
127.0.0.0      upa.luzhiai.net
127.0.0.1      1.jopenqc.com
127.0.0.0      www.guccia.net
127.0.0.1      1.joppnqq.com
127.0.0.0      4m9mnlmi.cn
127.0.0.1      1.xqhgm.com
127.0.0.0      mm119mkssd.cn
127.0.0.1      100.332233.com
127.0.0.0      61.128.171.115:8080
127.0.0.1      121.11.90.79
127.0.0.0      www.1119111.com
127.0.0.1      121565.net
127.0.0.0      win.nihao69.cn
127.0.0.1      125.90.88.38
127.0.0.1      16888.6to23.com
127.0.0.1      2.joppnqq.com
127.0.0.0      puc.lianxiac.net
127.0.0.1      204.177.92.68
127.0.0.0      pud.lianxiac.net
127.0.0.1      210.74.145.236
127.0.0.0      210.76.0.133
127.0.0.1      219.129.239.220
127.0.0.0      61.166.32.2
127.0.0.1      219.153.40.221
127.0.0.0      218.92.186.27
127.0.0.1      219.153.46.27
127.0.0.0      www.fsfsfag.cn
127.0.0.1      219.153.52.123
127.0.0.0      ovo.ovovov.cn
127.0.0.1      221.195.42.71
127.0.0.0      dw.com.com
127.0.0.1      222.73.218.115
127.0.0.1      203.110.168.233:80
127.0.0.1      3.joppnqq.com
127.0.0.1      203.110.168.221:80
127.0.0.1      363xx.com
127.0.0.1      www1.ip10086.com.cm
127.0.0.1      4199.com
127.0.0.1      blog.ip10086.com.cn
127.0.0.1      43242.com
127.0.0.1      www.ccji68.cn
127.0.0.1      5.xqhgm.com
127.0.0.0      t.myblank.cn
127.0.0.1      520.mm5208.com
127.0.0.0      x.myblank.cn
127.0.0.1      59.34.131.54
127.0.0.1      210.51.45.5
127.0.0.1      59.34.198.228
127.0.0.1      www.ew1q.cn
127.0.0.1      59.34.198.88
127.0.0.1      59.34.198.97
127.0.0.1      60.190.114.101
127.0.0.1      60.190.218.34
127.0.0.0      qq-xing.com.cn
127.0.0.1      60.191.124.252
127.0.0.1      61.145.117.212
127.0.0.1      61.157.109.222
127.0.0.1      75.126.3.216
127.0.0.1      75.126.3.217
127.0.0.1      75.126.3.218
127.0.0.0      59.125.231.177:17777
127.0.0.1      75.126.3.220
127.0.0.1      75.126.3.221
127.0.0.1      75.126.3.222
127.0.0.1      772630.com
127.0.0.1      832823.cn
127.0.0.1      8749.com
127.0.0.1      888.jopenqc.com
127.0.0.1      89382.cn
127.0.0.1      8v8.biz
127.0.0.1      97725.com
127.0.0.1      9gg.biz
127.0.0.1      www.9000music.com
127.0.0.1      test.591jx.com
127.0.0.1      a.topxxxx.cn
127.0.0.1      picon.chinaren.com
127.0.0.1      www.5566.net
127.0.0.1      p.qqkx.com
127.0.0.1      news.netandtv.com
127.0.0.1      z.neter888.cn
127.0.0.1      b.myblank.cn
127.0.0.1      wvw.wokutu.com
127.0.0.1      unionch.qyule.com
127.0.0.1      www.qyule.com
127.0.0.1      it.itjc.cn
127.0.0.1      www.linkwww.com
127.0.0.1      vod.kaicn.com
127.0.0.1      www.tx8688.com
127.0.0.1      b.neter888.cn
127.0.0.1      promote.huanqiu.com
127.0.0.1      www.huanqiu.com
127.0.0.1      www.haokanla.com
127.0.0.1      play.unionsky.cn
127.0.0.1      www.52v.com
127.0.0.1      www.gghka.cn
127.0.0.1      icon.ajiang.net
127.0.0.1      new.ete.cn
127.0.0.1      www.stiae.cn
127.0.0.1      o.neter888.cn
127.0.0.1      comm.jinti.com
127.0.0.1      www.google-analytics.com
127.0.0.1      hz.mmstat.com
127.0.0.1      www.game175.cn
127.0.0.1      x.neter888.cn
127.0.0.1      z.neter888.cn
127.0.0.1      p.etimes888.com
127.0.0.1      hx.etimes888.com
127.0.0.1      abc.qqkx.com
127.0.0.1      dm.popdm.cn
127.0.0.1      www.yl9999.com
127.0.0.1      www.dajiadoushe.cn
127.0.0.1      v.onondown.com.cn
127.0.0.1      www.interoo.net
127.0.0.1      bally1.bally-bally.net
127.0.0.1      www.bao5605509.cn
127.0.0.1      www.rty456.cn
127.0.0.1      www.werqwer.cn
127.0.0.1      1.360-1.cn
127.0.0.1      user1.23-16.net
127.0.0.1      www.guccia.net
127.0.0.1      www.interoo.net
127.0.0.1      upa.netsool.net
127.0.0.1      js.users.51.la
127.0.0.1      vip2.51.la
127.0.0.1      web.51.la
127.0.0.1      qq.gong2008.com
127.0.0.1      2008tl.copyip.com
127.0.0.1      tla.laozihuolaile.cn
127.0.0.1      www.tx6868.cn
127.0.0.1      p001.tiloaiai.com
127.0.0.1      s1.tl8tl.com
127.0.0.1      s1.gong2008.com
127.0.0.1      4b3ce56f9g.3f6e2cc5f0b.com
127.0.0.1      2be37c5f.3f6e2cc5f0b.com

==================================
进程特权扫描
特殊特权被允许: SeSystemtimePrivilege [PID = 1876, F:\WINDOWSMM\TROJANWALL.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1876, F:\WINDOWSMM\TROJANWALL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1876, F:\WINDOWSMM\TROJANWALL.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 584, I:\楼上服务器\WSYSCHECK\WSYSCHECK\WSYSCHECK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 584, I:\楼上服务器\WSYSCHECK\WSYSCHECK\WSYSCHECK.EXE]

==================================
计划任务
N/A

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT