瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 向各位大侠求助!我电脑中了一个不报毒也杀不掉的病毒

1   1  /  1  页   跳转

向各位大侠求助!我电脑中了一个不报毒也杀不掉的病毒

向各位大侠求助!我电脑中了一个不报毒也杀不掉的病毒

我电脑中了一个不报毒也杀不掉的病毒,向各位大侠求助!
具体中毒表现是:会在c盘Local Settings\Temp下生成win67, win34等等win**.exe的文件,出现时会闪现dos运行的黑色窗口,这些exe文件可以删除,但是还会出现。 我怀疑同是temp文件夹下的一个文件:Perflib_Perfdata_f24.dat , 但是无法删除,也无法改名。

不知大家有没有人遇到同样的问题,请各位帮忙指教!

谢谢!
最后编辑2006-12-19 21:35:49
分享到:
gototop
 

请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。

下载地址
http://www.kztechs.com/sreng/sreng2.zip

gototop
 

首先对大侠表示感谢!


System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Corporation]
(MsnMsgr)("C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background) [(Verified)Microsoft Corporation]
(MSMSGS)("C:\Program Files\Messenger\msmsgs.exe" /background) [(Verified)Microsoft Corporation]
(KASStart)("D:\Program Files\Kingsoft\KSysCleaner\KASStart.EXE" -Startup) [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(run)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(IMSCMig)(C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload) [(Verified)Microsoft Corporation]
(BigDogPath)(C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera) [N/A]
(VSOCheckTask)("C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask) [McAfee, Inc.]
(VirusScan Online)(C:\Program Files\McAfee.com\VSO\mcvsshld.exe) [McAfee, Inc.]
(OASClnt)(C:\Program Files\McAfee.com\VSO\oasclnt.exe) [McAfee, Inc.]
(MCAgentExe)(c:\PROGRA~1\mcafee.com\agent\mcagent.exe) [McAfee, Inc]
(MCUpdateExe)(C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe) [McAfee, Inc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(explorer.exe) [(Verified)Microsoft Corporation]
(Userinit)(userinit.exe) [(Verified)Microsoft Corporation]
(UIHost)(logonui.exe) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
({9C0CFA58-3A6F-51ba-9EFE-5320F4F62FB1})(C:\WINDOWS\system32\bdscheca100.dll) [N/A]
({1A404685-7563-4d02-B0F6-58B308A406A9})(d:\progra~1\grisoft\avgfre~1\tnhjpayf.dll) [N/A]
gototop
 

启动文件夹

N/A



--------------------------------------------------------------------------------



服务

[Human Interface Device Access / HidServ]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A)
[McAfee WSC Integration / McDetect.exe]
(c:\program files\mcafee.com\agent\mcdetect.exe)(McAfee, Inc)
[McAfee.com McShield / McShield]
(c:\PROGRA~1\mcafee.com\vso\mcshield.exe)(McAfee Inc.)
[McAfee Task Scheduler / McTskshd.exe]
(c:\PROGRA~1\mcafee.com\agent\mctskshd.exe)(McAfee, Inc)
[McAfee SecurityCenter Update Manager / mcupdmgr.exe]
(C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe)(McAfee, Inc)
[SmartLinkService / SLService]
(slserv.exe)()
[Windows DHCP Service / WinDHCPsvc]
(C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start)(Microsoft Corporation)



--------------------------------------------------------------------------------



驱动程序

[Mtlmnt5 / Mtlmnt5]
(system32\DRIVERS\Mtlmnt5.sys)(Smart Link)
[Mtlstrm / Mtlstrm]
(system32\DRIVERS\Mtlstrm.sys)()
[NaiAvFilter1 / NaiAvFilter1]
(system32\drivers\naiavf5x.sys)(McAfee Inc.)
[npkcrypt / npkcrypt]
(\??\D:\Program Files\Tencent\QQ\npkcrypt.sys)(INCA Internet Co., Ltd.)
[NtMtlFax / NtMtlFax]
(system32\DRIVERS\NtMtlFax.sys)(Smart Link)
[Direct Parallel Link Driver / Ptilink]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[RecAgent / RecAgent]
(\SystemRoot\system32\DRIVERS\RecAgent.sys)(Smart Link)
[Secdrv / Secdrv]
(system32\DRIVERS\secdrv.sys)(N/A)
[SiS315 / SiS315]
(system32\DRIVERS\sisgrp.sys)(Silicon Integrated Systems Corporation)
[Service for AC'97 Sample Driver (WDM) / SiS7012]
(system32\drivers\sis7012.sys)(Silicon Integrated Systems Corporation)
[SiS AGP Filter / sisagp]
(\SystemRoot\system32\DRIVERS\sisagp.sys)(Silicon Integrated Systems Corporation)
[SiSkp / SiSkp]
(system32\drivers\srvkp.sys)(N/A)
[SiS PCI Fast Ethernet Adapter Driver / SISNIC]
(system32\DRIVERS\sisnic.sys)(SiS Corporation)
[SmartLink AMR_PCI Driver / Slntamr]
(system32\DRIVERS\slntamr.sys)(Smart Link)
[SlNtHal / SlNtHal]
(system32\DRIVERS\Slnthal.sys)(Smart Link)
[SlWdmSup / SlWdmSup]
(system32\DRIVERS\SlWdmSup.sys)(Vireo Software)

gototop
 

浏览器加载项

[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated)
[AcroIEToolbarHelper Class]
{AE7CD045-E861-484f-8273-0445EE161910} (D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated)
[Adobe PDF]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} (D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated)
[McAfee VirusScan]
{BA52B914-B692-46c4-B683-905236F6F655} (c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.)
[Java Plug-in 1.3.1_03]
{8AD9C840-044E-11D1-B3E9-00805F499D93} (C:\Program Files\JavaSoft\JRE\1.3.1_03\bin\npjava131_03.dll, JavaSoft / Sun Microsystems, Inc.)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[McAfee.com Download+Installer Class]
{36C417C6-13C6-448B-9784-DD73A93B0582} (C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc)
[Adobe PDF]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} (D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated)
[McAfee.com Registry Class]
{4C29D864-C55A-46DD-865C-17A1B7CC1A1A} (C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc)
[McAfee.com Operating System Class]
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc)
[Microsoft Licensed Class Manager 1.0]
{5220CB21-C88D-11CF-B347-00AA00A28331} (C:\WINDOWS\system32\licmgr10.dll, Microsoft Corporation)
[McAfee.com File System Class]
{5940894F-4BA9-4FAC-ACFD-2F56F7CE0E3B} (C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc)
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} (C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation)
[AcroIEToolbarHelper Class]
{AE7CD045-E861-484F-8273-0445EE161910} (D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\system32\shdocvw.dll, N/A)
[McAfee VirusScan]
{BA52B914-B692-46C4-B683-905236F6F655} (c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.)
[DwnldGroupMgr Class]
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (C:\WINDOWS\system32\mcgdmgr.dll, McAfee, Inc)
[McAfee.com Shell Helper Class]
{CA145D71-4BCB-461D-BCBE-C01C42867380} (C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[McAfee.com Application Helper Class]
{D2D8D3C0-C750-4703-A6AD-75D6B578FFE6} (C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc)
[ADXAutoLive]
{E5212436-921F-44a3-8865-11C0B9BA4AF2} (C:\PROGRA~1\adx\autolive.dll, Microsoft Corporation)
[上传到QQ网络硬盘]
(D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A)
[使用迅雷下载]
(d:\Program Files\Thunder Network\Thunder\geturl.htm, N/A)
[使用迅雷下载全部链接]
(d:\Program Files\Thunder Network\Thunder\getAllurl.htm, N/A)
[导出到 Microsoft Office Excel(&X)]
(res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A)
[转换为 Adobe PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A)
[转换为现有 PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A)
[转换选定的链接为 Adobe PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A)
[转换选定的链接为现有 PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A)
[转换选项为 Adobe PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A)
[转换选项为现有 PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A)
[转换链接目标为 Adobe PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A)
[转换链接目标为现有 PDF]
(res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A)



--------------------------------------------------------------------------------
gototop
 

正在运行的进程

[PID: 416][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 472][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 500][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 548][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 560][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 704][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 784][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 820][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 872][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\adx\adx.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[C:\Program Files\adx\atloader.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[C:\Program Files\adx\urlcatch.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[C:\Program Files\adx\autolive.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 7.0.0.0]
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400]
[D:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs] [Adobe Systems Inc., 7.0.0.2004121400\0]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[c:\progra~1\mcafee.com\vso\mcvsshl.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\progra~1\mcafee.com\vso\ShlRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[D:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll] [Adobe Systems Inc., 7.0.0.2004121400\0]
[d:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, N/A]
[PID: 1208][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\AdobePDF.dll] [Adobe Systems Incorporated., 7.0.0.00]
[D:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS] [N/A, N/A]
[PID: 1388][c:\program files\mcafee.com\agent\mcdetect.exe] [McAfee, Inc, 6, 0, 0, 19]
[PID: 1408][c:\PROGRA~1\mcafee.com\vso\mcshield.exe] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\RES00\McShield.DLL] [McAfee Inc., 11.0.0.137]
[c:\PROGRA~1\mcafee.com\vso\FTL.Dll] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\naiann.dll] [McAfee, Inc., 10, 0, 0, 21]
[c:\PROGRA~1\mcafee.com\vso\mytilus.dll] [McAfee Inc., 11.0.0.151]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[C:\Program Files\McAfee.com\VSO\MCSCAN32.DLL] [McAfee, Inc., 5.1.00]
[PID: 1448][c:\PROGRA~1\mcafee.com\agent\mctskshd.exe] [McAfee, Inc, 6, 0, 0, 13]
[PID: 1484][c:\PROGRA~1\mcafee.com\vso\OasClnt.exe] [McAfee, Inc., 10, 0, 0, 24]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 1736][c:\program files\mcafee.com\vso\mcvsshld.exe] [McAfee, Inc., 10, 0, 0, 22]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 15]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\shared\mcuicfg\6,0,0,4\mcuicfg.dll] [McAfee, Inc, 6, 0, 0, 4]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[PID: 1760][c:\progra~1\mcafee.com\vso\mcvsescn.exe] [McAfee, Inc., 10, 0, 0, 20]
[c:\progra~1\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\EmScnRes.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\program files\mcafee.com\vso\vsoupd.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\McVsWorm.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\WormRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[PID: 1824][C:\WINDOWS\VM_STI.EXE] [BIGDOG, 4, 2, 610, 4]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\VM31bPrp.Ax] [Vimicro, 1.00.01.00]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 1860][C:\WINDOWS\system32\slserv.exe] [ , 2.80.00(24Apr2000)]
[PID: 1948][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1980][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 196][C:\Program Files\Messenger\msmsgs.exe] [Microsoft Corporation, 4.7.3001]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 380][c:\progra~1\mcafee.com\vso\mcvsftsn.exe] [McAfee, Inc., 10, 0, 0, 19]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 15]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[PID: 1776][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2764][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4052][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 3876][D:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 8, 120]
[D:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[C:\WINDOWS\system32\sasperf.dll] [N/A, N/A]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[D:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\Program Files\adx\urlcatch.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 2888][C:\Program Files\McAfee.com\Agent\mcagent.exe] [McAfee, Inc, 6, 0, 0, 16]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[C:\Program Files\McAfee.com\Agent\SCRes.dll] [McAfee, Inc, 6, 0, 0, 7]
[c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 15]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[PID: 3488][D:\Download\DubaTool_ten\DubaTool_ten\金山毒霸十个最流行专杀工具\金山毒霸最流行十个专杀工具\Duba_KeyLog.EXE] [Kingsoft Co., Ltd, 2004, 6, 11, 5]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 3888][D:\Download\DubaTool_ten\DubaTool_ten\金山毒霸十个最流行专杀工具\金山毒霸最流行十个专杀工具\Duba_Concept.EXE] [Kingsoft Co., Ltd, 2001, 12, 30, 20]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 1036][D:\Download\DubaTool_ten\DubaTool_ten\金山毒霸十个最流行专杀工具\金山毒霸最流行十个专杀工具\Duba_JXOnlineTroj.EXE] [Kingsoft Co., Ltd, 2004, 6, 1, 3]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 652][D:\Download\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\adx\bhomgr.dll] [Microsoft Corporation, 5, 1, 2606, 1213]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
gototop
 

文件关联

.TXT Error. [NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------



Winsock 提供者

N/A



--------------------------------------------------------------------------------



Autorun.inf

N/A



--------------------------------------------------------------------------------



HOSTS 文件

N/A

gototop
 

运行SREng2,使用“启动项目”--注册表--删除
({9C0CFA58-3A6F-51ba-9EFE-5320F4F62FB1})(C:\WINDOWS\system32\bdscheca100.dll) [N/A]
运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
[Windows DHCP Service / WinDHCPsvc]
(C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start)(Microsoft Corporation)
选择“删除服务”
点“设置”选择“否”
重启按F8进入安全模式下
显示隐藏文件
删除:
C:\WINDOWS\system32\bdscheca100.dll
C:\WINDOWS\system32\windhcp.ocx
gototop
 

我在这里谢谢 鸟儿天上飞 !我按你的方法做了,但是在安全模式里没有:C:\WINDOWS\system32\bdscheca100.dll
C:\WINDOWS\system32\windhcp.ocx
这两个文件,然后我重起后没有出现病毒的症状,
我想病毒应该已经删除了,谢谢大侠!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT