瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:机子总是自动关机重启,谁能帮我看看是什么病毒作崇吗

1   1  /  1  页   跳转

求助:机子总是自动关机重启,谁能帮我看看是什么病毒作崇吗

求助:机子总是自动关机重启,谁能帮我看看是什么病毒作崇吗

机子总是自动关机重启,谁能帮我看看是什么病毒作崇吗
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <MyApp><1>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
    <Kernel><C:\WINNT\bboy.exe>  [N/A]
    <Folder Service><qjinfo.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINNT\豪杰多~1.SCR>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[Indexing Service / cisvc]
  <C:\WINNT\System32\cisvc.exe><Microsoft Corporation>
[ClipBook / ClipSrv]
  <C:\WINNT\system32\clipsrv.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Fax Service / Fax]
  <C:\WINNT\system32\faxsvc.exe><Microsoft Corporation>
[NetMeeting Remote Desktop Sharing / mnmsrvc]
  <C:\WINNT\System32\mnmsrvc.exe><Microsoft Corporation>
[Distributed Transaction Coordinator / MSDTC]
  <C:\WINNT\System32\msdtc.exe><Microsoft Corporation>
[Windows Installer / MSIServer]
  <C:\WINNT\system32\msiexec.exe /V><Microsoft Corporation>
[Network DDE / NetDDE]
  <C:\WINNT\system32\netdde.exe><Microsoft Corporation>
[Network DDE DSDM / NetDDEdsdm]
  <C:\WINNT\system32\netdde.exe><Microsoft Corporation>
[NVIDIA Driver Helper Service / NVSvc]
  <C:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator]
  <C:\WINNT\System32\locator.exe><Microsoft Corporation>
[QoS RSVP / RSVP]
  <C:\WINNT\System32\rsvp.exe -s><Microsoft Corporation>
[Smart Card Helper / SCardDrv]
  <C:\WINNT\system32\scardsvr32.exe -v><Microsoft Corporation>
[Smart Card / SCardSvr]
  <C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[Performance Logs and Alerts / SysmonLog]
  <C:\WINNT\system32\smlogsvc.exe><Microsoft Corporation>
[Telnet / TlntSvr]
  <C:\WINNT\system32\tlntsvr.exe><Microsoft Corporation>
[Uninterruptible Power Supply / UPS]
  <C:\WINNT\System32\ups.exe><Microsoft Corporation>
[Utility Manager / UtilMan]
  <C:\WINNT\System32\UtilMan.exe><Microsoft Corporation>
[VRVWatchServer / VRVWatchServer]
  <"C:\WINNT\system32\WatchClient.exe" -service><N/A>

==================================
驱动程序
[Service for Avance AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Avance Logic, Inc.>
[dmboot / dmboot]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Keypro / Keypro]
  <C:\WINNT\SYSTEM32\DRIVERS\Keypro.SYS><Microsoft Corporation>
[Netgroup Packet Filter / NPF]
  <system32\drivers\npf.sys><N/A>
[nv / nv]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139/810x Family Fast Etnernet NIC NT Driver / rtl8139]
  <System32\DRIVERS\R8139n5.SYS><Realtek Semiconductor Corporation>
[Superk53 / Superk53]
  <\SystemRoot\System32\drivers\superk53.sys><Microsoft Corporation>
[Ufkey / Ufkey]
  <C:\WINNT\SYSTEM32\DRIVERS\Ufkey.SYS><Microsoft Corporation>
最后编辑2007-01-04 12:29:58
分享到:
gototop
 

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[豪杰超级解霸V8]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\Herosoft\HeroV8\STHSDVD.EXE, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[VehPrint.Printer]
  {165ECDEA-5DE9-4799-B20D-B7D177629194} <D:\驾驶证打印安装\VehPrint_web.ocx, TMRI>
[DrvPrint.Printer]
  {74CB644D-0696-4E5D-9EDD-E1543B89365A} <C:\WINNT\Downloaded Program Files\DrvPrint.ocx, TMRI>
[MeChatU Class]
  {BE9D5F13-40C1-44CA-9950-B9211E4B60DD} <C:\WINNT\Downloaded Program Files\MeChatUser.dll, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\System32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[豪杰超级解霸V8实时播放]
  <C:\Herosoft\HeroV8\MPURLGET.HTM, N/A>

==================================
正在运行的进程
[PID: 136][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 160][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 156][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6714]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 208][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.6700]
    [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 220][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 400][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 424][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINNT\system32\OLFMNT40.DLL]  [Microsoft Corporation, 9.0.98.0105]
    [C:\WINNT\system32\spool\PRTPROCS\W32X86\olfpnt40.dll]  [Microsoft Corporation, 9.0.98.0105]
[PID: 460][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 488][C:\WINNT\System32\nvsvc32.exe]  [NVIDIA Corporation, 6.13.10.2832]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 524][C:\WINNT\system32\regsvc.exe]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 620][C:\WINNT\system32\MSTask.exe]  [Microsoft Corporation, 4.71.2195.6704]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 328][C:\WINNT\system32\WatchClient.exe]  [N/A, 6, 6, 16, 21]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 736][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 744][C:\WINNT\system32\VrvEdp_m.exe]  [N/A, 6, 6, 20, 536]
    [C:\WINNT\system32\Cipherop.dll]  [Cipherop, 6, 6, 18, 17]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 764][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 864][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINNT\SYSTEM32\bboy.DLL]  [N/A, N/A]
    [C:\WINNT\system32\VrvKeyBoard.dll]  [, 1, 0, 0, 1]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
    [D:\解压\rarext.dll]  [N/A, N/A]
[PID: 928][C:\WINNT\system32\ntsd.exe]  [Microsoft Corporation, 5.00.2184.1]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 936][C:\WINNT\system32\Vrvsafec.exe]  [edp, 6, 4, 19, 15]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 948][C:\WINNT\system32\conime.exe]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 964][C:\WINNT\system32\vrvrf_c.exe]  [, 6, 6, 6, 11]
    [C:\WINNT\system32\vrvpwk.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\VrvKeyBoard.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\vrvfw_c.dll]  [, 1, 0, 0, 2]
    [C:\WINNT\system32\vrvrun_c.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\bkfile.dll]  [N/A, N/A]
    [C:\WINNT\system32\edpaudfliter.dll]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 1168][C:\WINNT\bboy.exe]  [N/A, N/A]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINNT\SYSTEM32\bboy.DLL]  [N/A, N/A]
[PID: 1188][C:\WINNT\system32\qjinfo.exe]  [N/A, N/A]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINNT\SYSTEM32\bboy.DLL]  [N/A, N/A]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1320][C:\WINNT\SYSTEM32\CMD.EXE]  [Microsoft Corporation, 5.00.2195.6656]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 20772][C:\WINNT\system32\QJINFO.EXE]  [N/A, N/A]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 18776][C:\WINNT\system32\QJINFO.EXE]  [N/A, N/A]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 16460][C:\WINNT\system32\CMD.EXE]  [Microsoft Corporation, 5.00.2195.6656]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 15620][C:\WINNT\system32\QJINFO.EXE]  [N/A, N/A]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 29904][C:\WINNT\system32\psexec.exe]  [Sysinternals, 1.31]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 29720][C:\WINNT\System32\PSEXESVC.EXE]  [Sysinternals, 1.23]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
[PID: 15616][C:\Program Files\全国非税收入收缴管理系统\单位版\czsf_dw.exe]  [, 3.0.0.69]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINNT\SYSTEM32\bboy.DLL]  [N/A, N/A]
    [C:\WINNT\system32\VrvKeyBoard.dll]  [, 1, 0, 0, 1]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 29868][C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.473\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINNT\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
    [C:\WINNT\SYSTEM32\bboy.DLL]  [N/A, N/A]
    [C:\WINNT\system32\VrvKeyBoard.dll]  [, 1, 0, 0, 1]

==================================
文件关联
.TXT  Error. [notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
gototop
 

没人帮我看看吗
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT