我刚刚修复了一下,伞变绿了,看一会儿变不变了,变了的话,就是中毒了!我用windows清理助手发现了一个特洛伊木马。。。。。。
下面的是报告,哪位能看懂看一下。
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[Trojan]
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\DR WATSON\CPUSH.EXE
C:\PROGRAM FILES\GAME\HTMLPEEK.DLL
D:\SYSTEM VOLUME INFORMATION\_RESTORE{7CDF5ABD-0534-46BB-A886-60457EDD007B}\RP97\A0018453.EXE
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[SeaBar]
HKEY_CLASSES_ROOT\INTERFACE\{F08555AF-9CC3-11D2-AA8E-000000000000}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{F08555AF-9CC3-11D2-AA8E-000000000000}
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[Soso Address Search]
C:\PROGRAM FILES\TENCENT\SSPLUS\
C:\PROGRAM FILES\TENCENT\SSPLUS\SADDR1.DLL
C:\PROGRAM FILES\TENCENT\SSPLUS\SDATA.DAT
C:\PROGRAM FILES\TENCENT\SSPLUS\SPLUS.DLL
C:\PROGRAM FILES\TENCENT\SSPLUS\STDTBH.DAT
C:\WINDOWS\SYSTEM32\SCRAX.DLL
C:\WINDOWS\SYSTEM32\SSUP.DLL
HKEY_CLASSES_ROOT\CLSID\{0C7C23EF-A848-485B-873C-0ED954731014}
HKEY_CLASSES_ROOT\CLSID\{669751ED-D558-49AE-B01A-3B374CC7910E}
HKEY_CLASSES_ROOT\CLSID\{A57E074F-56D8-4A33-8112-AAC9693AA909}
HKEY_CLASSES_ROOT\CLSID\{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{0C7C23EF-A848-485B-873C-0ED954731014}
HKEY_CURRENT_USER\SOFTWARE\TENCENT\TBH
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{0C7C23EF-A848-485B-873C-0ED954731014}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{669751ED-D558-49AE-B01A-3B374CC7910E}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{90B1ECB2-FC3B-49AE-A6BD-F5F11BF5C4AD}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{A57E074F-56D8-4A33-8112-AAC9693AA909}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\TBH
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\STUP.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED\{669751ED-D558-49AE-B01A-3B374CC7910E}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\TENCENT BROWSER HELPER
HKEY_LOCAL_MACHINE\SOFTWARE\TENCENT\TBH
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[Soso Toolbar]
HKEY_CLASSES_ROOT\CLSID\{90B1ECB2-FC3B-49AE-A6BD-F5F11BF5C4AD}
HKEY_CLASSES_ROOT\INTERFACE\{3084BC3D-C0D6-4A28-A8A4-5857165886EE}
HKEY_CLASSES_ROOT\TCTRL.TWEB
HKEY_CLASSES_ROOT\TYPELIB\{B1A7C2CF-BF40-4597-8142-7615D74D0CC3}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{3084BC3D-C0D6-4A28-A8A4-5857165886EE}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{B1A7C2CF-BF40-4597-8142-7615D74D0CC3}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED\{0C7C23EF-A848-485B-873C-0ED954731014}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED\{A57E074F-56D8-4A33-8112-AAC9693AA909}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELL EXTENSIONS\APPROVED\{DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9}
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[BaiduSearchPartner]
HKEY_CLASSES_ROOT\BDPLUGINS.INTERCEPTOR
HKEY_CLASSES_ROOT\BDPLUGINS.INTERCEPTOR.1
HKEY_CLASSES_ROOT\CLSID\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[BaiduSuperSoBa]
C:\WINDOWS\DOWNLOADED PROGRAM FILES\BDPLUGIN.DLL
C:\WINDOWS\DOWNLOADED PROGRAM FILES\BDSRHOOK.DLL
HKEY_CLASSES_ROOT\BAIDUBAR.BAIDU
HKEY_CLASSES_ROOT\BAIDUBAR.BAIDU.1
HKEY_CLASSES_ROOT\BAIDUBAREX.BANDIE
HKEY_CLASSES_ROOT\BAIDUBAREX.BANDIE.1
HKEY_CLASSES_ROOT\BAIDUBAREX.BDHOMEPAGE
HKEY_CLASSES_ROOT\BAIDUBAREX.BDHOMEPAGE.1
HKEY_CLASSES_ROOT\BDHLPROBJ.BDHLPROBJ
HKEY_CLASSES_ROOT\BDHLPROBJ.BDHLPROBJ.1
HKEY_CLASSES_ROOT\BDHOOK.BDSRCHHOOK
HKEY_CLASSES_ROOT\BDHOOK.BDSRCHHOOK.1
HKEY_CLASSES_ROOT\BDHOOK.URLBDHOOK
HKEY_CLASSES_ROOT\BDHOOK.URLBDHOOK.1
HKEY_CLASSES_ROOT\CLSID\{18AF9E61-B5BC-48B0-884F-2C1D9E73C962}
HKEY_CLASSES_ROOT\CLSID\{2C5AA40E-8814-4EB6-876E-7EFB8B3F9662}
HKEY_CLASSES_ROOT\CLSID\{CA92B524-BC8A-4610-BD2C-6BD3E28155D0}
HKEY_CLASSES_ROOT\CLSID\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}
HKEY_CLASSES_ROOT\INTERFACE\{A294F8EB-86D9-4C4A-8B3E-909253761C64}
HKEY_CLASSES_ROOT\TYPELIB\{3034F39C-A0B3-4068-9C0C-FC566B0263A3}
HKEY_CLASSES_ROOT\TYPELIB\{6AFC2761-1253-427C-9A56-385B4609BE1D}
HKEY_CLASSES_ROOT\TYPELIB\{AFC3CDEF-B447-4146-AFA2-91C754468BC4}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{2C5AA40E-8814-4EB6-876E-7EFB8B3F9662}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7F05EE4-0426-454F-8013-C41E3596E9E9}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIDUBAREX.BANDIE
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIDUBAREX.BANDIE.1
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{18AF9E61-B5BC-48B0-884F-2C1D9E73C962}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{2C5AA40E-8814-4EB6-876E-7EFB8B3F9662}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{CA92B524-BC8A-4610-BD2C-6BD3E28155D0}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{A294F8EB-86D9-4C4A-8B3E-909253761C64}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{3034F39C-A0B3-4068-9C0C-FC566B0263A3}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{6AFC2761-1253-427C-9A56-385B4609BE1D}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{AFC3CDEF-B447-4146-AFA2-91C754468BC4}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\ACCESSIBILITY\BDSEARCH
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\BDHELPER
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[3721Keyword]
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6354ABE6-05F1-49ED-B850-E423120EC338}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD00D911-7529-4084-9946-A29F1BDF4FE5}
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[Yahoo Toolbar]
HKEY_CLASSES_ROOT\CLSID\{9C3C2C08-C494-4F52-AE94-85156A447D43}
HKEY_CLASSES_ROOT\INTERFACE\{A9267C5F-A4A5-4BD3-B78B-80C497F32EDE}
HKEY_CLASSES_ROOT\INTERFACE\{CBEF989D-7C4C-4354-928C-EA81D055EE7C}
HKEY_CLASSES_ROOT\TYPELIB\{04D0FD01-C8FA-413B-AD83-519D10B93324}
HKEY_CLASSES_ROOT\YPHOTOSEASY.PHOTOSCTRL
HKEY_CLASSES_ROOT\YPHOTOSEASY.PHOTOSCTRL.1
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{9C3C2C08-C494-4F52-AE94-85156A447D43}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{9C3C2C08-C494-4F52-AE94-85156A447D43}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{A9267C5F-A4A5-4BD3-B78B-80C497F32EDE}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{CBEF989D-7C4C-4354-928C-EA81D055EE7C}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{04D0FD01-C8FA-413B-AD83-519D10B93324}
HKEY_LOCAL_MACHINE\SOFTWARE\YAHOO\ASSISTANT
HKEY_LOCAL_MACHINE\SOFTWARE\YAHOO\ASSISTANT\ASSIST
[2.8.0.8.0728 - 2.8.2.8.0805]
2008-08-12 18:02
[QQ Toolbar]
C:\PROGRAM FILES\TENCENT\QQTOOLBAR\
C:\PROGRAM FILES\TENCENT\QQTOOLBAR\IEBAR.DLL
HKEY_CLASSES_ROOT\CLSID\{29CF293A-1E7D-4069-9E11-E39698D0AF95}
HKEY_CLASSES_ROOT\CLSID\{FB46BBEE-B3D5-46BF-94F4-A6C1A17F0A28}
HKEY_CLASSES_ROOT\SOSOIEBAR.IEBAROBJ
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{29CF293A-1E7D-4069-9E11-E39698D0AF95}
HKEY_CURRENT_USER\SOFTWARE\TENCENT\QQTOOLBAR
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{29CF293A-1E7D-4069-9E11-E39698D0AF95}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{FB46BBEE-B3D5-46BF-94F4-A6C1A17F0A28}
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\SOSOIEBAR.IEBAROBJ
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{29CF293A-1E7D-4069-9E11-E39698D0AF95}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\QQTOOLBAR
HKEY_LOCAL_MACHINE\SOFTWARE\TENCENT\QQTOOLBAR