瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

1   1  /  1  页   跳转

[求助] 完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

[CODE]
2008-08-06,21:02:17
System Repair Engineer 2.6.11.992
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <QQDownload><"D:\Program Files\Tencent\QQDownload\QQDownload.exe" autostart>  [File is missing]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <LenSoft><C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe>  []
    <NeroCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <MS-4011 Memory Patch><D:\程序补丁\RavSasser.exe -Patch>  [File is missing]
    <360Safetray><d:\Program Files\360safe\safemon\360tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <Lskbdrv><C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe>  []
    <runeip><"d:\Program Files\Rising\AntiSpyware\rstray.exe" /startup>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><kmon.dll>  [(Verified)Beijing Rising Information Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
    <N/A><"C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
==================================

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; QQDownload 1.7)
分享到:
gototop
 

回复:完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

启动文件夹
N/A

==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
  <d:\Program Files\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>

==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[basic2 / basic2][Stopped/Manual Start]
  <System32\DRIVERS\HSF_BSC2.sys><Conexant>
[CALLKEY_IO / CALLKEY_IO][Stopped/Manual Start]
  <\??\C:\Program Files\OneKey\CALLKEY.sys><N/A>
[HSFHWBS2 / HSFHWBS2][Running/Manual Start]
  <System32\DRIVERS\HSFHWBS2.sys><Conexant Systems>
[HSF_DP / HSF_DP][Running/Manual Start]
  <System32\DRIVERS\HSF_DP.sys><Conexant Systems>
[hsf_msft / hsf_msft][Stopped/Manual Start]
  <System32\DRIVERS\HSF_MSFT.sys><Conexant>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <System32\DRIVERS\mdmxsdk.sys><Conexant>
[MSJDrvr / MSJDrvr][Running/System Start]
  <System32\DRIVERS\MSJDrvr.sys><N/A>
[New0 / New0][Stopped/Auto Start]
  <\??\C:\WINDOWS\System32\new.sys><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Rksample / Rksample][Stopped/Manual Start]
  <System32\DRIVERS\HSF_SAMP.sys><Conexant>
[RsAntiSpyware / RsAntiSpyware][Running/Disabled]
  <System32\drivers\RsBoot.sys><N/A>
[Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
  <System32\DRIVERS\R8139n51.SYS><Realtek Semiconductor Corporation>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
  <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[TesSafe / TesSafe][Stopped/Manual Start]
  <\??\C:\WINDOWS\System32\TesSafe.sys><TENCENT>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\drivers\UIUSys.sys><Conexant>
[winachsf / winachsf][Running/Manual Start]
  <System32\DRIVERS\HSF_CNXT.sys><Conexant Systems>

==================================
浏览器加载项
[QQCycloneHelper Class]
  {00000000-12C9-4305-82F9-43058F20E8D2} <D:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[卡卡上网安全助手]
  {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\WINDOWS\System32\urlFilter.dll, Beijing Rising Information Technology Co., Ltd.>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, 360.CN>
[浩方对战平台]
  {0A155D3C-68E2-4215-A47A-E800A446447A} <D:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[联想]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[RavOnline Class]
  {9FAFB576-6933-4CCC-AB3D-B988EC43D04E} <C:\WINDOWS\Downloaded Program Files\RavOLCtl.dll, Beijing Rising Technology Co., Ltd.>
[ScreenCapture Class]
  {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} <C:\WINDOWS\System32\TXGYMailActiveX.dll, Tencent Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
[PasswordEditCtrl Class]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\System32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[XMP Class]
  {6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
  {693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin17.dll, Thunder Networking Technologies,LTD>
[360SafeLive]
  {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\Program Files\360safe\live.dll, 360.cn>
[DapCtrl Class]
  {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.1.5804.62.(249).dll, ShenZhen Thunder Networking Technologies Ltd.>
[Thunder DapPlayer]
  {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <d:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer3.0.5712.71.249.dll, ShenZhen Thunder Networking Technologies Ltd.>
[XPPlayer Class]
  {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Program Files\Common Files\Thunder Network\KanKan\PPlayer.2.0.5833.183.(249).dll, Xunlei Networking Technologies,LTD>
[&使用超级旋风下载]
  <D:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
  <D:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
[使用迅雷下载]
  <d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
gototop
 

回复:完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

==================================
正在运行的进程
[PID: 448 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 496 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 520 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 564 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 752 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 804 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 908 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 936 / LOCAL SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1088 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1332 / l][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1002]
[PID: 1476 / l][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.09]
[PID: 1484 / l][C:\Program Files\Lenovo\幸福一键通\FlyShuttle.exe]  [, 1, 0, 0, 1]
    [C:\Program Files\Lenovo\幸福一键通\CLxUI.dll]  [联想(北京)有限公司, 1, 0, 0, 1]
    [C:\Program Files\Lenovo\幸福一键通\SKOSD.DLL]  [Silitek Corp., 1, 0, 6, 0]
    [C:\Program Files\Lenovo\幸福一键通\SKUtil.DLL]  [Silitek Corp., 1, 0, 9, 0]
    [C:\Program Files\Lenovo\幸福一键通\VolumeOsd.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\ScrOSD32.dll]  [N/A, ]
[PID: 1532 / l][C:\Program Files\Lenovo\幸福一键通\Kbdriver.exe]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\lxkeyled.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\VolumeOsd.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\ScrOSD32.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\tgekb.dll]  [N/A, ]
    [C:\Program Files\Lenovo\幸福一键通\XPNyGet.dll]  [N/A, ]
[PID: 1564 / l][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1572 / l][C:\WINDOWS\System32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\NVMCTRAY.DLL]  [NVIDIA Corporation, 6.14.01.4351]
[PID: 1600 / l][D:\Program Files\Tencent\QQDownload\QQDownload.exe]  [Tencent Technology (Shenzhen) Company Limited, 1, 8, 201, 201]
    [D:\Program Files\Tencent\QQDownload\xmain.dll]  [Tencent Technology (Shenzhen) Company Limited, 1, 8, 202, 202]
    [D:\Program Files\Tencent\QQDownload\xcore.dll]  [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 90]
    [C:\WINDOWS\System32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.9]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1002]
[PID: 1464 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1496 / SYSTEM][d:\Program Files\StormII\stormliv.exe]  [北京暴风网际科技有限公司, 3, 8, 3, 15]
    [d:\Program Files\StormII\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
[PID: 1624 / SYSTEM][C:\WINDOWS\System32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.01.4351]
[PID: 1708 / LOCAL SERVICE][C:\WINDOWS\System32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 2376 / l][C:\Program Files\ChinaNet\VnetClient.exe]  [, 2005, 11, 14, 1]
    [C:\Program Files\ChinaNet\Communicate.dll]  [0, 2005, 3, 3, 1]
    [C:\Program Files\ChinaNet\DialModule.dll]  [GDCN, 2007, 4, 4, 16]
    [C:\Program Files\ChinaNet\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]  [, 2005, 7, 27, 1]
    [C:\PROGRA~1\ChinaNet\sign.dll]  [0, 2004, 12, 1, 1]
    [C:\PROGRA~1\ChinaNet\PostPlug.dll]  [, 2004, 12, 16, 2]
    [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]  [, 2005, 10, 13, 1]
    [C:\PROGRA~1\ChinaNet\Gif89a.dll]  [, 2005, 6, 21, 1]
    [C:\PROGRA~1\ChinaNet\VnetBs.ocx]  [, 2004, 11, 18, 1]
    [C:\PROGRA~1\ChinaNet\ACCOUN~2.DLL]  [, 2005, 11, 14, 1]
    [C:\PROGRA~1\ChinaNet\AccountMgr.dll]  [, 2007, 3, 22, 10]
    [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]  [GDDC, 2005, 11, 14, 1]
    [C:\PROGRA~1\ChinaNet\DialogStyle.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\ChinaNet\Timer.ocx]  [, 2007, 3, 28, 17]
    [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]  [, 2005, 2, 24, 1]
    [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]  [, 2005, 8, 26, 1]
    [C:\PROGRA~1\ChinaNet\PassCtrl.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\System32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\WINDOWS\System32\pthreadVC.dll]  [N/A, ]
    [C:\WINDOWS\System32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\PROGRA~1\ChinaNet\PlugPush.dll]  [, 2004, 12, 21, 1]
    [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]  [, 2004, 11, 23, 1]
    [C:\PROGRA~1\ChinaNet\VNETLO~1.OCX]  [, 2005, 10, 9, 1]
    [C:\PROGRA~1\ChinaNet\StatNum.dll]  [, 2004, 11, 18, 1]
    [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]  [, 2005, 3, 2, 1]
    [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]  [GDCN, 2005, 10, 9, 1]
    [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]  [, 2005, 9, 13, 9]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
[PID: 3020 / l][D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\FetionVM.exe]  [China Mobile, 1.0.0.0]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\rsdeploy.dll]  [Remotesoft Inc., 1, 0, 6, 0]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\FetionVM.rsm]  [N/A, ]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\v2.0.50727\MSVCR80.dll]  [N/A, ]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\c\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll]  [Microsoft Corporation, 2.0.50727.1433 (REDBITS.050727-1400)]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\c\windows\assembly\NativeImages_v2.0.50727_32\FetionVM\a87393057972c752eb50061d4235f9ec\FetionVM.ni.exe]  [China Mobile, 1.0.0.0]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\System\System.Windows.Forms.dll]  [Microsoft Corporation, 2.0.50727.214 (QFE.050727-2100)]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\System\System.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [D:\Program Files\China Mobile\Fetion\ImpsControls.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\System\System.Drawing.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [D:\Program Files\China Mobile\Fetion\ImpsPcBase.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\System\System.Xml.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [D:\Program Files\China Mobile\Fetion\ImpsClientBase.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\ImpsClientUtils.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\ImpsClientResource.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\ImpsClientCore.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\ImpsBase.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\System\Accessibility.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [D:\Program Files\China Mobile\Fetion\VmDotNet\v2.0.50727\System\System.Configuration.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [D:\Program Files\China Mobile\Fetion\NCindy.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\Interop.DynamicGifCtlLib.dll]  [ , 1.0.0.0]
    [D:\Program Files\China Mobile\Fetion\ImpsPcCommLayer.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\ImpsClientData.dll]  [China Mobile, 3.0.0.0]
    [D:\Program Files\China Mobile\Fetion\SQLite.Interop.DLL]  [, 1.0.44.0]
    [D:\Program Files\China Mobile\Fetion\sensmon.dll]  [China Mobile, 1.0.0.1]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1002]
    [D:\Program Files\China Mobile\Fetion\Interop.WMPLib.dll]  [ , 1.0.0.0]
    [D:\Program Files\China Mobile\Fetion\AxInterop.WMPLib.dll]  [, 1.0.0.0]
[PID: 184 / l][C:\WINDOWS\System32\wuauclt.exe]  [Microsoft Corporation, 5.4.3630.1106 (xpsp1.020828-1920)]
[PID: 916 / l][D:\Program Files\QQ\TXPlatform.exe]  [Tencent, 1, 0, 170, 0]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1002]
[PID: 2808 / l][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1240 / l][d:\Program Files\Rising\AntiSpyware\rstray.exe]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.15]
    [d:\Program Files\Rising\AntiSpyware\rsmginfo.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8]
    [d:\Program Files\Rising\AntiSpyware\RsXML.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2]
    [d:\Program Files\Rising\AntiSpyware\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [d:\Program Files\Rising\AntiSpyware\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [d:\Program Files\Rising\AntiSpyware\ComServ.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.31]
    [d:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [d:\Program Files\Rising\AntiSpyware\rscommon.dll]  [Beijing Rising Information Technology Co., Ltd., 20.0.1.1]
    [d:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.24]
    [d:\Program Files\Rising\AntiSpyware\pngdll.dll]  [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5]
    [d:\Program Files\Rising\AntiSpyware\runiep.dll]  [Beijing Rising Information Technology Co., Ltd., 6.0.0.32]
[PID: 1192 / l][d:\Program Files\Rising\AntiSpyware\knownsvr.exe]  [Beijing Rising Information Technology Co., Ltd., 6.0.0.11]
    [d:\Program Files\Rising\AntiSpyware\NComm.dll]  [Beijing Rising Information Technology Co., Ltd., 6.0.0.6]
    [C:\WINDOWS\System32\kmon.dll]  [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 21]
    [d:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.24]
    [d:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[PID: 3056 / l][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\kmon.dll]  [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 21]
    [d:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.24]
    [d:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1002]
    [D:\Program Files\Tencent\QQDownload\QQIEHelper01.dll]  [腾讯公司, 1, 1, 0, 5]
    [c:\PROGRA~1\chinanet\VNETTR~1.DLL]  [, 2005, 4, 6, 1]
    [c:\PROGRA~1\chinanet\Communicate.dll]  [0, 2005, 3, 3, 1]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\WINDOWS\System32\urlFilter.dll]  [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15]
    [d:\Program Files\Rising\AntiSpyware\UrlRule.dll]  [Beijing Rising Information Technology Co., Ltd., 1.0.0.15]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
[PID: 1360 / l][D:\Program Files\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.6.11.992]
[PID: 2648 / l][D:\Program Files\sreng2\SRE92d82068.EXE]  [Smallfrogs Studio, 2.6.11.992]
    [C:\WINDOWS\System32\kmon.dll]  [Beijing Rising Information Technology Co., Ltd., 1, 0, 0, 21]
    [d:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.24]
    [d:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 1, 5, 1002]
    [D:\Program Files\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1484, C:\PROGRAM FILES\LENOVO\幸福一键通\FLYSHUTTLE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1532, C:\PROGRAM FILES\LENOVO\幸福一键通\KBDRIVER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1600, D:\PROGRAM FILES\TENCENT\QQDOWNLOAD\QQDOWNLOAD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2376, C:\PROGRAM FILES\CHINANET\VNETCLIENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3020, D:\PROGRAM FILES\CHINA MOBILE\FETION\VMDOTNET\V2.0.50727\FETIONVM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1360, D:\PROGRAM FILES\SRENG2\SRENGLDR.EXE]

==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高,  被下面模块所HOOK: 0x003B5875)
入口点错误:NtCreateKey (危险等级: 高,  被下面模块所HOOK: 0x003B5A15)
入口点错误:NtLoadDriver (危险等级: 高,  被下面模块所HOOK: 0x003B6165)
入口点错误:NtSetValueKey (危险等级: 高,  被下面模块所HOOK: 0x003B5AE5)
入口点错误:NtWriteFile (危险等级: 高,  被下面模块所HOOK: 0x003B5945)
入口点错误:ZwCreateFile (危险等级: 高,  被下面模块所HOOK: 0x003B5875)
入口点错误:ZwCreateKey (危险等级: 高,  被下面模块所HOOK: 0x003B5A15)
入口点错误:ZwSetValueKey (危险等级: 高,  被下面模块所HOOK: 0x003B5AE5)
入口点错误:ZwWriteFile (危险等级: 高,  被下面模块所HOOK: 0x003B5945)
入口点错误:CreateServiceA (危险等级: 高,  被下面模块所HOOK: 0x003B5E25)
入口点错误:CreateServiceW (危险等级: 高,  被下面模块所HOOK: 0x003B5EF5)
入口点错误:LoadLibraryA (危险等级: 高,  被下面模块所HOOK: 0x003B6B55)
入口点错误:CreateFileA (危险等级: 高,  被下面模块所HOOK: 0x003B6A55)
入口点错误:CreateFileW (危险等级: 高,  被下面模块所HOOK: 0x003B6645)
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: 0x003B5BB5)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: 0x003B5C85)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

回复:完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

浏览网页总是说没有响应!而且很卡!
gototop
 

回复: 完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

1.用XDelBox勾选抑制再生后删除以下文件:(XDelBox1.7支持奥运版下载)

使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入不检查路径,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。

C:\WINDOWS\System32\DRIVERS\MSJDrvr.sys
C:\WINDOWS\System32\new.sys

2.删除重启后使用SREng修复下面各项:

启动项目 -- 服务-- 驱动程序之如下项删除:

[MSJDrvr / MSJDrvr][Running/System Start]  <System32\DRIVERS\MSJDrvr.sys><N/A>
[New0 / New0][Stopped/Auto Start]    <\??\C:\WINDOWS\System32\new.sys><N/A>

最后用以下软件清理一次并更新杀毒软件至最新进行全盘杀毒一次

清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe
下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip
gototop
 

回复:完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

C:\WINDOWS\System32\DRIVERS\MSJDrvr.sys
C:\WINDOWS\System32\new.sys
[MSJDrvr / MSJDrvr][Running/System Start]  <System32\DRIVERS\MSJDrvr.sys><N/A>
[New0 / New0][Stopped/Auto Start]    <\??\C:\WINDOWS\System32\new.sys><N/A>

以上的都删了吧
gototop
 

回复:完蛋啦!连 SRE都被修改了!请大家帮帮忙吧!

用XDELBOX,ICESWORD
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT