1   1  /  1  页   跳转

[求助] 中毒了~~~求助

中毒了~~~求助

360卫士不好用  电脑超慢




+ 注册表自运行项目
  + 系统服务
    + HKLM\System\CurrentControlSet\Services
      aspnet_state
        [A ] 1. c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe

      clr_optimization_v2.0.50727_32
        [A ] 2. c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe

      IDriverT
        [A ] 3. c:\program files\common files\installshield\driver\1050\intel 32\idrivert.exe

      Ntfrs
        [AM] 4. c:\windows\system32\ntfrs.exe

      O&O Defrag
        [AM] 5. c:\windows\system32\oodag.exe

      O2Flash
        [AM] 6. c:\windows\system32\o2flash.exe

      ose
        [A ] 7. c:\program files\common files\microsoft shared\source engine\ose.exe

      RfwProxySrv
        [A ] 8. c:\program files\rising\rfw\rfwproxy.exe

      RfwService
        [A ] 9. c:\program files\rising\rfw\rfwsrv.exe

      RsCCenter
        [A ] 10. c:\program files\rising\rav\ccenter.exe

      RsRavMon
        [A ] 11. c:\program files\rising\rav\ravmond.exe

      usnjsvc
        [A ] 12. c:\program files\windows live\messenger\usnsvc.exe

      WLSetupSvc
        [A ] 13. c:\program files\windows live\installer\wlsetupsvc.exe


  + 内核驱动
    + HKLM\System\CurrentControlSet\Services
      001766b9
        [A ] 14. c:\windows\system32\drivers\001766b9.sys

      BaseTDI
        [A ] 15. c:\windows\system32\drivers\basetdi.sys

      BRGSp50
        [A ] 16. c:\windows\system32\drivers\brgsp50.sys

      ExpScaner
        [A ] 17. c:\program files\rising\rav\expscan.sys

      HBKernel
        [A ] 18. c:\windows\system32\drivers\hbkernel.sys

      HDAudBus
        [A ] 19. c:\windows\system32\drivers\hdaudbus.sys

      HookCont
        [A ] 20. c:\program files\rising\rav\hookcont.sys

      HookReg
        [A ] 21. c:\program files\rising\rav\hookreg.sys

      HookSys
        [A ] 22. c:\program files\rising\rav\hooksys.sys

      HookUrl
        [A ] 23. c:\program files\rising\rfw\hookurl.sys

      ialm
        [A ] 24. c:\windows\system32\drivers\ialmnt5.sys

      IntcAzAudAddService
        [A ] 25. c:\windows\system32\drivers\rtkhdaud.sys

      MEMSCAN
        [A ] 26. c:\program files\rising\rav\memscan.sys

      O2MDRDR
        [A ] 27. c:\windows\system32\drivers\o2media.sys

      O2SDRDR
        [A ] 28. c:\windows\system32\drivers\o2sd.sys

      RfwBase
        [A ] 29. c:\windows\system32\drivers\rfwbase.sys

      RsFwDrv
        [A ] 30. c:\program files\rising\rfw\rsfwdrv.sys

      RsNTGDI
        [A ] 31. c:\windows\system32\drivers\rsntgdi.sys

      RSPPSYS
        [A ] 32. c:\program files\rising\rav\rsppsys.sys

      RTL8023xp
        [A ] 33. c:\windows\system32\drivers\rtnicxp.sys

      SafeBoxKrnl
        [A ] 34. c:\program files\360safebox\safeboxkrnl.sys

      Secdrv
        [A ] 35. c:\windows\system32\drivers\secdrv.sys

      ZD1211BU(TP-LINK)
        [A ] 36. c:\windows\system32\drivers\zd1211bu.sys

      ZDPSp50
        [A ] 37. c:\windows\system32\drivers\zdpsp50.sys


  + 系统登陆自运行
    + HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
      igfxcui
        [A ] 38. c:\windows\system32\igfxdev.dll


  + IE浏览器加载模块
    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
      {01443AEC-0FD1-40fd-9C87-E93D1494C233}
        [AM] 39. c:\program files\thunder network\thunder\comdlls\tdatonce_now.dll

      {889D2FEB-5411-4565-8998-1DD2C5261283}
        [AM] 40. c:\program files\thunder network\thunder\comdlls\xunleibho_now.dll

      {9030D464-4C02-4ABF-8ECC-5164760863C6}
        [AM] 41. c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll

      {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}
        [AM] 42. c:\windows\system32\urlfilter.dll

    + HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
      Exec
        [A ] 43. c:\program files\thunder network\thunder\thunder.exe


  + 资源管理器加载模块
    + HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
      application/octet-stream
        [A ] 44. c:\windows\system32\mscoree.dll

      application/x-complus
        [A ] 44. c:\windows\system32\mscoree.dll

      application/x-msdownload
        [A ] 44. c:\windows\system32\mscoree.dll

      text/xml
        [A ] 45. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll

    + HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
      livecall
        [A ] 46. c:\program files\windows live\messenger\msgrapp.8.5.1302.1018.dll

      msnim
        [A ] 46. c:\program files\windows live\messenger\msgrapp.8.5.1302.1018.dll

      mso-offdap
        [A ] 47. c:\program files\common files\microsoft shared\web components\10\owc10.dll

      mso-offdap11
        [A ] 48. c:\program files\common files\microsoft shared\web components\11\owc11.dll

    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
      HyperTerminal Icon Ext
        [A ] 49. c:\windows\system32\hticons.dll

      Portable Media Devices
        [A ] 50. c:\windows\system32\audiodev.dll

      Portable Media Devices Menu
        [A ] 50. c:\windows\system32\audiodev.dll

      WinRAR shell extension
        [AM] 51. d:\program files\winrar\rarext.dll

      Shell Extensions for RealOne Player
        [A ] 52. d:\program files\real\realplayer\rpshell.dll

      Web Folders
        [A ] 53. c:\program files\common files\microsoft shared\web folders\msonsext.dll

      Microsoft Office Outlook Desktop Icon Handler
        [A ] 54. c:\program files\microsoft office\office11\mlshext.dll

      Microsoft Office Outlook Custom Icon Handler
        [A ] 55. c:\program files\microsoft office\office11\olkfstub.dll

      Microsoft Office HTML Icon Handler
        [AM] 56. c:\program files\microsoft office\office11\msohev.dll

      RISING
        [AM] 57. c:\windows\system32\ravext.dll

      UnlockerShellExtension
        [AM] 58. d:\program files\unlocker\unlockercom.dll

      Messenger Sharing Folders
        [A ] 59. c:\program files\windows live\messenger\fsshext.8.5.1302.1018.dll

      ShellLink for Application References
        [A ] 60. c:\windows\system32\dfshim.dll

      Shell Icon Handler for Application References
        [A ] 60. c:\windows\system32\dfshim.dll

    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
      {2876D76C-CAAA-4313-AF97-8D1D9A2A1087}
        [AM] 61. c:\windows\system32\dpvvoxmh.dll

      {2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}
        [AM] 62. c:\windows\system32\tscfgwmijxsj.dll

      {76D44356-B494-443a-BEDC-AA68DE4255E6}
        [AM] 63. c:\windows\system32\dispexcb.dll

      {F0930A2F-D971-4828-8209-B7DFD266ED44}
        [AM] 64. c:\windows\system32\xolehlpjh.dll

      {E0F3526A-4165-4589-80CD-50B6FBAC3BDA}
        [AM] 65. c:\windows\system32\adsntzt.dll

      {00180018-0018-0018-0018-00180018BB15}
        [AM] 66. c:\windows\system32\mstimewd.dll

      {DA56B183-A731-402b-9235-2CB8803E212D}
        [AM] 67. c:\windows\system32\imgutilhx2.dll

      {71A78CD4-E470-4a18-8457-E0E0283DD507}
        [AM] 68. c:\windows\system32\lweurqhx.dll

      {21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}
        [AM] 69. c:\windows\system32\unqqcnqn.dll

      {A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}
        [AM] 70. c:\windows\system32\nwapi32dj.dll

      {E560642D-A32D-432c-9E7E-9A135CC37E0F}
        [AM] 71. c:\windows\system32\kbdgrms.dll

      {9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}
        [AM] 72. c:\windows\system32\certmgrkd.dll

      {D3112B69-A745-4805-874E-ABD480EA1299}
        [AM] 73. c:\windows\system32\bootvidgj.dll

      {7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}
        [AM] 74. c:\windows\system32\cliconfgzx.dll

      {65056902-6E7B-4bd7-95BA-688DB5FA5BEB}
        [AM] 66. c:\windows\system32\mstimewd.dll

    + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
      dpvvoxmh.dll
        [AM] 61. c:\windows\system32\dpvvoxmh.dll

      tscfgwmijxsj.dll
        [AM] 62. c:\windows\system32\tscfgwmijxsj.dll

      dispexcb.dll
        [AM] 63. c:\windows\system32\dispexcb.dll

      xolehlpjh.dll
        [AM] 64. c:\windows\system32\xolehlpjh.dll

      adsntzt.dll
        [AM] 65. c:\windows\system32\adsntzt.dll

      mstimewd.dll
        [AM] 66. c:\windows\system32\mstimewd.dll

      imgutilhx2.dll
        [AM] 67. c:\windows\system32\imgutilhx2.dll

      lweurqhx.dll
        [AM] 68. c:\windows\system32\lweurqhx.dll

      cohqervo.dll
        [AM] 69. c:\windows\system32\unqqcnqn.dll

      nwapi32dj.dll
        [AM] 70. c:\windows\system32\nwapi32dj.dll

      kbdgrms.dll
        [AM] 71. c:\windows\system32\kbdgrms.dll

      certmgrkd.dll
        [AM] 72. c:\windows\system32\certmgrkd.dll

      bootvidgj.dll
        [AM] 73. c:\windows\system32\bootvidgj.dll

      cliconfgzx.dll
        [AM] 74. c:\windows\system32\cliconfgzx.dll

      excrythu.dll
        [AM] 69. c:\windows\system32\unqqcnqn.dll

      bvkkyglz.dll
        [AM] 69. c:\windows\system32\unqqcnqn.dll

      fuywdlcj.dll
        [AM] 69. c:\windows\system32\unqqcnqn.dll

      pjmqvpqu.dll
        [AM] 69. c:\windows\system32\unqqcnqn.dll

      unqqcnqn.dll
        [AM] 69. c:\windows\system32\unqqcnqn.dll


  + 用户登陆自运行项目
    + HKCU\Software\Microsoft\Windows\CurrentVersion\Run
      msnmsgr
        [AM] 75. c:\program files\windows live\messenger\msnmsgr.exe

    + HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      RavTask
        [A ] 76. c:\program files\rising\rav\ravtask.exe

      TkBellExe
        [AM] 77. c:\program files\common files\real\update_ob\realsched.exe

      RfwMain
        [AM] 78. c:\program files\rising\rfw\rfwmain.exe

      360Safebox
        [AM] 79. c:\program files\360safebox\safeboxtray.exe

      runeip
        [AM] 80. c:\program files\rising\antispyware\rstray.exe


  + 开机执行
    + HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
      BootExecute
        [A ] 81. c:\windows\system32\bsmain.exe


  + 映像劫持
    + HKCR\.html
      htmlfile\Edit\Command
        [A ] 82. c:\program files\microsoft office\office11\msohtmed.exe

      htmlfile\Print\Command
        [A ] 82. c:\program files\microsoft office\office11\msohtmed.exe

    + HKCR\.htm
      htmlfile\Edit\Command
        [A ] 82. c:\program files\microsoft office\office11\msohtmed.exe

      htmlfile\Print\Command
        [A ] 82. c:\program files\microsoft office\office11\msohtmed.exe

    + HKCR\.mp3
      RealPlayer.MP3.6\open\Command
        [A ] 83. d:\program files\real\realplayer\realplay.exe


  + 打印机监控
    + HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
      Microsoft Document Imaging Writer Monitor
        [AM] 84. c:\windows\system32\mdimon.dll


+ 其他自启动项目
  + C:\Documents and Settings\All Users\「开始」菜单\程序\启动
    TL-WN322G_WN322G+客户端应用程序.lnk
      [AM] 85. d:\program files\zdwlan.exe


+ 正在运行的进程
  + 00000088(136) Explorer.EXE
    01730000[00009000]
      [AM] 61. c:\windows\system32\dpvvoxmh.dll

    017C0000[00008000]
      [AM] 62. c:\windows\system32\tscfgwmijxsj.dll

    10000000[0006C000]
      [AM] 63. c:\windows\system32\dispexcb.dll

    015C0000[00008000]
      [AM] 64. c:\windows\system32\xolehlpjh.dll

    01860000[00008000]
      [AM] 65. c:\windows\system32\adsntzt.dll

    01870000[00009000]
      [AM] 66. c:\windows\system32\mstimewd.dll

    01880000[00008000]
      [AM] 67. c:\windows\system32\imgutilhx2.dll

    01B20000[00009000]
      [AM] 68. c:\windows\system32\lweurqhx.dll

    01BB0000[00008000]
      [AM] 69. c:\windows\system32\unqqcnqn.dll

    01C40000[00009000]
      [AM] 70. c:\windows\system32\nwapi32dj.dll

    01CD0000[0000A000]
      [AM] 71. c:\windows\system32\kbdgrms.dll

    01D60000[0006C000]
      [AM] 72. c:\windows\system32\certmgrkd.dll

    01E50000[0006C000]
      [AM] 73. c:\windows\system32\bootvidgj.dll

    01F40000[0006C000]
      [AM] 74. c:\windows\system32\cliconfgzx.dll

    72C80000[00008000]
      [ M] 86. c:\windows\system32\msacm32.drv

    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

    032A0000[0002C000]
      [AM] 39. c:\program files\thunder network\thunder\comdlls\tdatonce_now.dll

    032D0000[00031000]
      [AM] 40. c:\program files\thunder network\thunder\comdlls\xunleibho_now.dll

    240A0000[0000E000]
      [ M] 89. c:\program files\thunder network\thunder\components\resworker\dsbho_01.dll

    24050000[0001E000]
      [ M] 90. c:\program files\thunder network\thunder\components\resworker\dataprocessor_01.dll

    01100000[0002C000]
      [AM] 51. d:\program files\winrar\rarext.dll

    00FE0000[00006000]
      [AM] 58. d:\program files\unlocker\unlockercom.dll

    01130000[0001B000]
      [AM] 57. c:\windows\system32\ravext.dll

    36D30000[0001A000]
      [ M] 91. c:\program files\microsoft office\office11\mcps.dll

  + 000000fc(252) knownsvr.exe
    00400000[00072000]
      [ M] 92. c:\program files\rising\antispyware\knownsvr.exe

    10000000[0002F000]
      [ M] 93. c:\program files\rising\antispyware\ncomm.dll

    00A80000[00030000]
      [ M] 94. c:\program files\rising\antispyware\comx3.dll

    00AB0000[00019000]
      [ M] 95. c:\program files\rising\antispyware\syslay.dll

  + 000001f8(504) smss.exe
  + 00000234(564) csrss.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 00000250(592) winlogon.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

    72C80000[00008000]
      [ M] 86. c:\windows\system32\msacm32.drv

  + 0000027c(636) services.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 00000288(648) lsass.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 00000320(800) svchost.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 0000035c(860) svchost.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 00000394(916) svchost.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

    50E60000[0000C000]
      [ M] 96. c:\windows\system32\wups2.dll

  + 000003c4(964) svchost.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 00000400(1024) svchost.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 00000548(1352) rfwstub.exe
    00400000[00017000]
      [ M] 97. c:\program files\rising\rfw\rfwstub.exe

    7C3A0000[0007B000]
      [ M] 98. c:\windows\system32\msvcp71.dll

    7C340000[00056000]
      [ M] 99. c:\windows\system32\msvcr71.dll

    23700000[00028000]
      [ M] 100. c:\program files\rising\rfw\rscommon.dll

    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

  + 000005b8(1464) spoolsv.exe
    70000000[00019000]
      [ M] 87. c:\program files\rising\rfw\ijt_base.dll

    75000000[0000F000]
      [ M] 88. c:\program files\rising\rfw\olemon.dll

    00E70000[00008000]
      [AM] 84. c:\windows\system32\mdimon.dll

    00EC0000[00008000]
      [ M] 101. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll

  + 000005d4(1492) RfwMain.exe
    00400000[00092000]
      [AM] 78. c:\program files\rising\rfw\rfwmain.exe

    7C140000[00103000]
      [ M] 102. c:\windows\system32\mfc71.dll

    7C340000[00056000]
      [ M] 99. c:\windows\system32\msvcr71.dll

    7C3A0000[0007B000]
      [ M] 98. c:\windows\system32\msvcp71.dll

    26600000[000A8000]
      [ M] 103. c:\program files\rising\rfw\rsguilib.dll

    10000000[0000E000]
      [ M] 104. c:\program files\rising\rfw\rsappmgr.dll

    00B60000[00030000]
      [ M] 105. c:\program files\rising\rfw\cfgdll.dll

    23700000[00028000]
      [ M] 100. c:\program files\rising\rfw\rscommon.dll

    00DB0000[00014000]
      [ M] 106. c:\program files\rising\rfw\rfwctrl.dll

    23800000[00022000]
      [ M] 107. c:\program files\rising\rfw\rsxml.dll

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
分享到:
gototop
 

回复:中毒了~~~求助


没人看这个日志的

确实有病毒的

1.扫日志前关闭无用进程,如QQ,迅雷及播放器程序

2.到官方下载SReng
下载地址
http://www.kztechs.com/sreng/download.html
SREng/智能扫描

等扫描完成,保存日志(LOG格式)

PS:如主程序SREng**.exe无法运行,导致无法扫描日志
将主程序改名为小狮子.bat

3.为了最大程度减少对病毒的误判,和对病毒准确定位,最好同时上传金山清理专家日志
下载金山清理专家
http://www.duba.net/qing/

金山清理专家-在线系统诊断(隐藏安全项)-导出诊断报告-(全选)-导出报告

(4.如都以上软件无法正常运行
尝试该版本SRENG

http://bbs.ikaka.com/attachment.aspx?attachmentid=412527
如2.6的能用,还是用2.6的,2.4的就免了

5.2份日志/报告以附件上传(点击我回的贴的右下角的“引用”,然后就应该知道怎么以附件发了),贴到反病毒区.已发帖请跟贴,勿另开新帖。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT