12   1  /  2  页   跳转

跪求各位高手!!

跪求各位高手!!

我的电脑中了病毒,每隔一段时间就弹出个网页,网页的名字是www.djdj163.com或者是http://myad.91ivr.com/?seo=2504或者是http://code.balashow.com/full/118.html?u=1843。IE的左烂历史里面有这三个网名,我用最新版的KAKA,喀吧斯基,EWIDO,魔法兔子,3721都试过了,杀不到,在安全模式下也没杀到,我实在是没办法了,如果哪个高人能解决,小弟感激涕淋。拜托了!!

附件附件:

下载次数:502
文件类型:application/octet-stream
文件大小:
上传时间:2006-11-23 11:23:04
描述:



最后编辑2006-11-23 12:20:00
分享到:
gototop
 

请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。

下载地址
http://www.kztechs.com/sreng/sreng2.zip

gototop
 

2006-11-23,11:19:40

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <CoolSwitch><C:\WINDOWS\system32\taskswitch.exe>  [N/A]
    <NVMixerTray><"C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe">  [NVIDIA Corporation]
    <KAVPersonal50><"d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize>  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <ATICCC><; "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay>  [N/A]
    <Messager.exe><; C:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <Messenger.exe><; C:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <Realplayer.exe><; C:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
gototop
 

启动文件夹
N/A

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[kavsvc / kavsvc]
  <"d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe"><Kaspersky Lab>
[Network Notification / Network Notification]
  <C:\WINDOWS\system32\ShellUninstall\scvhcot.exe><Microsoft Corporation>
[Remote Access Auto Connection Manager / RasAuto]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\rasaute_2.dll><N/A>
[Windows IntelligentStart / Windows IntelligentStart]
  <C:\Windows\system32\rpeCache\servrpe.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\mspmsnsv.dll><Microsoft Corporation>

==================================
gototop
 

驱动程序
[3275906 / 3275906]
  <C:\WINDOWS\SYSTEM32\DRIVERS\3275906.SYS><N/A>
[3859281 / 3859281]
  <C:\WINDOWS\SYSTEM32\DRIVERS\3859281.SYS><N/A>
[89625 / 89625]
  <C:\WINDOWS\SYSTEM32\DRIVERS\89625.SYS><N/A>
[ati2mtag / ati2mtag]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Kl1 / Kl1]
  <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[Klif / Klif]
  <System32\drivers\klif.sys><Kaspersky Labs>
[Klmc / Klmc]
  <System32\drivers\klmc.sys><Kaspersky Lab>
[npkcrypt / npkcrypt]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nvatabus / nvatabus]
  <\SystemRoot\system32\DRIVERS\nvatabus.sys><NVIDIA Corporation>
[Service for NVIDIA(R) nForce(TM) Audio Enumerator / nvax]
  <system32\drivers\nvax.sys><NVIDIA Corporation>
[NVIDIA Disk Cache Filter Driver / nvcchflt]
  <\SystemRoot\system32\DRIVERS\nvcchflt.sys><NVIDIA Corporation>
[Service for NVIDIA(R) nForce(TM) Audio / nvnforce]
  <system32\drivers\nvapu.sys><NVIDIA Corporation>
[Motorola USB Device / P2k]
  <system32\DRIVERS\P2k.sys><Motorola Inc>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TSP / TSP]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Labs>
gototop
 

==================================
浏览器加载项
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[卡卡上网安全助手]
  {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\FLASH.OCX, Macromedia, Inc.>

==================================
正在运行的进程
[PID: 488][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 544][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 576][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4129]
[PID: 620][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 632][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 784][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4129]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 808][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 868][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1060][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1092][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1240][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4129]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 1328][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
[PID: 1420][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1624][C:\WINDOWS\system32\taskswitch.exe]  [N/A, N/A]
[PID: 1636][C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe]  [NVIDIA Corporation, 1.0.451]
    [C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerZHC.dll]  [NVIDIA Corporation, 1.0.451]
    [C:\Program Files\Common Files\NVIDIA Shared\Audio\NVAudioMod.dll]  [NVIDIA Corporation, 1.0.451]
[PID: 1652][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1868][C:\WINDOWS\system32\ShellUninstall\scvhcot.exe]  [Microsoft Corporation, 5, 1, 2600, 2180]
[PID: 1892][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\rasaute_2.dll]  [N/A, N/A]
[PID: 1496][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1500][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3616][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3668][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2144][d:\Program Files\Maxthon\max.exe]  [Maxthon International Ltd., 1, 5, 3, 18]
gototop
 

[d:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [d:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  [Kaspersky Lab, 5.0.1.18]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll]  [Kaspersky Lab, 5.0.388.2]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\tempfile.ppl]  [Kaspersky Lab, 5.0.388.0]
    [C:\WINDOWS\system32\Macromed\Flash\FLASH.OCX]  [Macromedia, Inc., 7,0,19,0]
[PID: 1876][D:\Program Files\BitComet\BitComet.exe]  [www.BitComet.com, 0.57.]
[PID: 2712][D:\Program Files\Maxthon\Max.exe]  [Maxthon International Ltd., 1, 5, 3, 18]
    [D:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  [Kaspersky Lab, 5.0.1.18]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll]  [Kaspersky Lab, 5.0.388.2]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\tempfile.ppl]  [Kaspersky Lab, 5.0.388.0]
    [D:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
[PID: 916][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3224][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  [Kaspersky Lab, 5.0.1.18]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll]  [Kaspersky Lab, 5.0.388.2]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\tempfile.ppl]  [Kaspersky Lab, 5.0.388.0]
[PID: 2808][D:\Program Files\Maxthon\Max.exe]  [Maxthon International Ltd., 1, 5, 3, 18]
gototop
 

[D:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  [Kaspersky Lab, 5.0.1.18]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll]  [Kaspersky Lab, 5.0.388.2]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll]  [Kaspersky Lab, 5.0.388.1]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll]  [Kaspersky Lab, 5.0.388.0]
    [d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl]  [Kaspersky Lab, 5.0.388.0]
    [d:\program files\kaspersky lab\kaspersky anti-virus personal pro\tempfile.ppl]  [Kaspersky Lab, 5.0.388.0]
    [D:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
[PID: 2508][C:\Documents and Settings\djlgood\桌面\sreng2\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
gototop
 

就这些了
gototop
 



运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
Network Notification
Remote Access Auto Connection Manager
Windows IntelligentStart
Portable Media Serial Number Service
,选择“删除服务”
点“设置”选择“否”

运行(双击)SRENG2,点“启动项目,服务,点“驱动程序”
勾选“隐藏微软服务”选中病毒服务
3275906
3859281
89625
,选择“删除服务”
点“设置”选择“否”


运行SREng2,使用“启动项目”--注册表--删除
Messager.exe><; C:\Program Files\Tencent\QQ\Messenger.exe> [N/A]
<Messenger.exe><; C:\Program Files\Tencent\QQ\Messenger.exe> [N/A]
<Realplayer.exe><; C:\Program Files\Tencent\QQ\Messenger.exe> [N/A]

重启按F8进入安全模式下
显示隐藏文件
删除:                     
C:\WINDOWS\system32\ShellUninstall\scvhcot.exe
C:\WINDOWS\system32\rasaute_2.dll
C:\WINDOWS\system32\mspmsnsv.dll
C:\Windows\system32\rpeCache\servrpe.exe
C:\WINDOWS\SYSTEM32\DRIVERS\3275906.SYS
C:\WINDOWS\SYSTEM32\DRIVERS\3859281.SYS
C:\WINDOWS\SYSTEM32\DRIVERS\89625.SYS
C:\Program Files\Tencent\QQ\Messenger.exe
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT