1   1  /  1  页   跳转

急,如何查杀Trojan.PSW.Lmir.kdb

急,如何查杀Trojan.PSW.Lmir.kdb

近来中了木马Trojan.PSW.Lmir.kdb,求助各位大哥,它该怎么查杀???
最后编辑2006-07-29 16:27:46
分享到:
gototop
 

请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改
gototop
 

2006-07-28,23:12:05

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 98 SE  -

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <internat.exe><internat.exe>  [Microsoft Corporation]
    <ScanRegistry><C:\WINDOWS\scanregw.exe /autorun>  [Microsoft Corporation]
    <TaskMonitor><C:\WINDOWS\taskmon.exe>  [Microsoft Corporation]
    <SystemTray><SysTray.Exe>  [Microsoft Corporation]
    <LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>  [Microsoft Corporation]
    <C-Media Mixer><C:\WINDOWS\NewMixer.exe /startup>  [C-Media Electronic Inc. (www.cmedia.com.tw)]
    <SysExplr><C:\HEROSOFT\Hero3000\SYSEXPLR.EXE>  []
    <YOKAssiant><Rundll32.exe C:\PROGRA~1\YOK.COM\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant>  [www.yok.com]
    <thunder_mini><C:\PROGRAM FILES\MAXTHON\THUNDERMINI\ThunderMini.exe>  [深圳市三代科技开发有限公司]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <ThunderMini><C:\Program Files\Thunder Network\ThunderMini\ThunderMiniShell.exe>  []
    <CriticalUpdate><C:\WINDOWS\SYSTEM\wucrtupd.exe -startup>  [Microsoft Corporation]
    <WebThunder><C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WebThunder.exe>  [深圳市迅雷网络技术有限公司]
    <NMGameX_AutoRun><C:\WINDOWS\Rundll32.exe NMGAMEX.DLL,LiveProcess /aa>  []
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>  [Microsoft Corporation]
    <SchedulingAgent><mstask.exe>  [Microsoft Corporation]
    <RfwService><"C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE" -service>  [Beijing Rising Technology Co., Ltd.]
    <KB918547><C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE>  [Microsoft Corporation]
    <KB891711><C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE>  [Microsoft Corporation]
    <RsCcenter><"C:\Program Files\Rising\Rav\CCenter.exe">  [Beijing Rising Technology Co., Ltd.]
    <RavMond><"C:\Program Files\Rising\Rav\RavMond.exe">  [Beijing Rising Technology Co., Ltd.]
    <RavMon><"C:\Program Files\Rising\Rav\RavMon.exe" -system>  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
[Microsoft Office]
  <C:\WINDOWS\Start Menu\Programs\启动\Microsoft Office.lnk><N>

==================================
服务

==================================
浏览器加载项
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\PROGRAM FILES\TENCENT\QQ\QQIEHELPER.DLL, 深圳市腾讯计算机系统有限公司>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\SYSTEM\XUNLEIBHO_V8.DLL, Thunder Networking Technologies,LTD>
[ThunderMini Browser Helper]
  {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\COMDLLS\XUNLEIMINIBHO_001.DLL, Thunder Networking Technologies,LTD>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WEBTHUNDERBHO_010.DLL, Thunder Networking Technologies,LTD>
[珊瑚虫工具栏]
  {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} <C:\PROGRAM FILES\YOK.COM\SUPERSEARCH\YOK_SUPERSEARCH.DLL, www.yok.com>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[解霸]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\HEROSOFT\Hero3000\MPLAYER.EXE, N/A>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\PROGRAM FILES\TENCENT\QQ\QQIEHELPER.DLL, 深圳市腾讯计算机系统有限公司>
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[Update Class]
  {9F1C11AA-197B-4942-BA54-47A8489BB47F} <C:\WINDOWS\SYSTEM\IUCTL.DLL, Microsoft Corporation>
[解霸实时播放]
  <C:\HEROSOFT\Hero3000\MPURLGET.HTM, N/A>
[珊瑚虫搜索]
  <C:\PROGRAM FILES\YOK.COM\SUPERSEARCH\yoksch.htm, N/A>
[&使用迷你迅雷下载]
  <C:\PROGRAM FILES\MAXTHON\THUNDERMINI\geturl.htm, N/A>
[使用Web迅雷下载]
  <C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\GetUrl.htm, N/A>
[&使用迅雷下载]
  <C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\getallurl.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 4294954555][C:\WINDOWS\SYSTEM\MPREXE.EXE]  <Microsoft Corporation><4.10.1998>
[PID: 4294866751][C:\WINDOWS\SYSTEM\MSTASK.EXE]  <Microsoft Corporation><4.71.1972.1>
    [C:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
    [C:\PROGRAM FILES\RISING\RFW\RFWAPI.DLL]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
[PID: 4294855579][C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
[PID: 4294877975][C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\PROGRAM FILES\RISING\RAV\EXTMAIL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\PROGRAM FILES\RISING\RAV\RSSTORE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
    [C:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [C:\PROGRAM FILES\RISING\RAV\NVFILE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\PROGRAM FILES\RISING\RAV\SCANEX.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\PROGRAM FILES\RISING\RAV\UNEXE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\PROGRAM FILES\RISING\RAV\ENGINE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\PROGRAM FILES\RISING\RAV\SPAMENG.DLL]  <N/A><18, 0, 0, 6>
    [C:\PROGRAM FILES\RISING\RAV\MAILMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RAV\MEMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL]  <rising><18, 0, 0, 2>
    [C:\PROGRAM FILES\RISING\RAV\REGMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL]  <Rising><18, 1, 0, 9>
    [C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
[PID: 4294883879][C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 29>
    [C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[PID: 4294877163][C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
    [C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[PID: 4294033855][C:\WINDOWS\SYSTEM\RPCSS.EXE]  <Microsoft Corporation><4.71.2900>
    [C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4293952611][C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[PID: 4294852067][C:\WINDOWS\SYSTEM\INTERNAT.EXE]  <Microsoft Corporation><4.10.2222>
[PID: 4294132395][C:\WINDOWS\TASKMON.EXE]  <Microsoft Corporation><4.10.1998>
[PID: 4294137503][C:\WINDOWS\SYSTEM\SYSTRAY.EXE]  <Microsoft Corporation><4.10.2222>
    [C:\WINDOWS\SYSTEM32\CMNPROP.DLL]  <C-Media Corporation><5.00.2195.11>
[PID: 4294155755][C:\WINDOWS\NEWMIXER.EXE]  <C-Media Electronic Inc. (www.cmedia.com.tw)><1.55>
    [C:\HEROSOFT\HERO3000\SYS936.DLL]  <N/A><N/A>
[PID: 4294180771][C:\HEROSOFT\HERO3000\SYSEXPLR.EXE]  <N/A><N/A>
    [C:\HEROSOFT\HERO3000\COOLMENU.DLL]  <N/A><N/A>
    [C:\HEROSOFT\HERO3000\AVCDROM.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\WNASPI32.DLL]  <Adaptec><1, 0, 0, 0>
[PID: 4294164487][C:\PROGRAM FILES\MAXTHON\THUNDERMINI\THUNDERMINI.EXE]  <深圳市三代科技开发有限公司><1, 1, 0, 4>
    [C:\PROGRAM FILES\MAXTHON\THUNDERMINI\BOOST_THREAD-VC6-MT-1_31.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\IEMBED01.DLL]  < ><2, 1, 0, 30>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\IEMBEDSHELL.DLL]  < ><1, 0, 0, 7>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\UPDATEEXEC.DLL]  <Thunder Networking Technologies,LTD><1, 0, 1, 5>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\UPDATEDOWNLOAD.DLL]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\HISTORYINFO_MANAGE.DLL]  <Thunder Networking Technologies,LTD><5, 2, 0, 150>
gototop
 

[PID: 4294069403][C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WEBTHUNDER.EXE]  <深圳市迅雷网络技术有限公司><1, 0, 4, 28>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\TASKMANAGE.DLL]  <Thunder Networking Technologies,LTD><1, 0, 4, 25>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\DOWNLOAD_INTERFACE.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
    [C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4294138059][C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294293975][C:\WINDOWS\SYSTEM\WMIEXE.EXE]  <Microsoft Corporation><5.00.1755.1>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\IEMBED01.DLL]  < ><2, 1, 0, 30>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL]  < ><1, 0, 0, 6>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\PROGRAM\UPDATEDOWNLOAD.DLL]  <Thunder Networking Technologies,LTD><1, 0, 1, 6>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\PROGRAM\DOWNLOAD_INTERFACE.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
[PID: 4294305615][C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\PROGRAM\THUNDERMINI.EXE]  <Thunder Networking Technologies,LTD><2, 0, 0, 29>
[PID: 4294232723][C:\WINDOWS\SYSTEM\PSTORES.EXE]  <Microsoft Corporation><5.00.1877.3>
    [C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\PROGRAM FILES\YOK.COM\SUPERSEARCH\YOK_SUPERSEARCH.DLL]  <www.yok.com><2.0.1.6>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WEBTHUNDERBHO_010.DLL]  <Thunder Networking Technologies,LTD><6, 0, 0, 1>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\COMDLLS\XUNLEIMINIBHO_001.DLL]  <Thunder Networking Technologies,LTD><2, 0, 0, 1>
    [C:\WINDOWS\SYSTEM\RAVEXT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
[PID: 4294109195][C:\WINDOWS\EXPLORER.EXE]  <Microsoft Corporation><4.72.3110.1>
    [C:\WINDOWS\SYSTEM\UPENGINE.DLL]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\SYSTEM\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX]  <Macromedia, Inc.><6,0,84,0>
    [C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\PROGRAM FILES\MAXTHON\SERVICES\REALTIME\REAL_TIME.DLL]  <$><1, 0, 0, 1>
    [C:\PROGRAM FILES\THUNDER NETWORK\WEBTHUNDER\WEBTHUNDERBHO_010.DLL]  <Thunder Networking Technologies,LTD><6, 0, 0, 1>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDERMINI\COMDLLS\XUNLEIMINIBHO_001.DLL]  <Thunder Networking Technologies,LTD><2, 0, 0, 1>
[PID: 4294118335][C:\PROGRAM FILES\MAXTHON\MAX.EXE]  <Maxthon International Ltd.><1, 5, 3, 18>
    [C:\PROGRAM FILES\MAXTHON\MAXZLIB.DLL]  < ><1, 0, 0, 2>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\DD620_32.DLL]  <Silicon Integrated Systems Corp.><4.11.01.1060>
[PID: 4294415683][C:\WINDOWS\SYSTEM\DDHELP.EXE]  <Microsoft Corporation><4.09.00.0900>
    [C:\WINDOWS\SYSTEM\RAVEXT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\REGISTERDLL.DLL]  <Thunder Networking Technologies,LTD><1, 0, 1, 4>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\ITHUNDER.DLL]  <Thunder Networking Technologies,LTD><1, 0, 0, 30>
[PID: 4278793711][C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\THUNDER.EXE]  <Thunder Networking Technologies,LTD><5.0.5.97>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\HISTORYINFO_MANAGE.DLL]  <Thunder Networking Technologies,LTD><5, 0, 0, 73>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\UPDATEDOWNLOAD.DLL]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\DOWNLOAD_INTERFACE.DLL]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\LOG4CPLUS.DLL]  < ><1, 0, 2, 1>
    [C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\STLPORT_VC646.DLL]  <STLport Consulting, Inc.><4.6.2003.1031>
[PID: 4278947471][C:\MY DOCUMENTS\SRENG2\SRENG2\SRENG.EXE]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [C:\WINDOWS\winhlp32.exe %1]
.INI  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  Error. [超级解霸3000]
.JS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

完毕,希望大家帮忙!
gototop
 

楼主是98的系统,很多与XP不一样的.
我看不出什么问题,还是等论坛上的高手看看吧.
楼主能说说病毒路径吗?
gototop
 

用sreng  切换到启动项 删除<KB918547><C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE> [Microsoft Corporation]
<KB891711><C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE> [Microsoft Corporation]
重启计算机
删除C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT