瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】中毒了,瑞星自动删除TTplayer.exe,提示Trojan.DL.MnLess.fm

12   1  /  2  页   跳转

【求助】中毒了,瑞星自动删除TTplayer.exe,提示Trojan.DL.MnLess.fm

【求助】中毒了,瑞星自动删除TTplayer.exe,提示Trojan.DL.MnLess.fm

最初是在办公室用笔记本发现的问题,当时正在用千千听歌,提示重起后删除。我就重起,后来文件倒是删除了,可是连千千一起删了。但是不能没播放器啊,就又装上了千千,但装上重起后又自动删除了,而且第二次删除瑞星历史记录里没有反应。
初步判断中毒了,但是肯定还有部分瑞星没查出来。
今天刚把U盘插到台式机上,台式就又出现这一幕,TTplayer.exe被删除。我机器设置禁止U盘自动播放了的啊!而且打开所有隐藏也没在U盘里发现半个文件。
哪位大侠发个话啊,救救啊。
最后编辑2007-03-30 17:52:12
分享到:
gototop
 

SRE 日志上来
gototop
 

[CODE]

2007-03-29,20:12:25

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
    <BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}><"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe">  [Nero AG]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <BigDogPath><C:\WINDOWS\VM_STI.EXE ZSMC USB PC Camera>  [N/A]
    <pdfFactory Pro 分配器 v2><"C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM>  [FinePrint Software, LLC]
    <SKYNET Personal FireWall><D:\PROGRA~1\SkyNet\Firewall\pfw.exe>  [广州众达天网技术有限公司]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <RavStub><"D:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <KernelFaultCheck><C:\WINDOWS\System32\wdm.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
N/A

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\System32\Ati2evxx.exe><>
[ATI Smart / ATI Smart][Stopped/Auto Start]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NBService / NBService][Stopped/Manual Start]
  <D:\Program Files\Ahead\Nero 7\Nero BackItUp\NBService.exe><Nero AG>
[Pml Driver HPZ12 / Pml Driver HPZ12][Running/Auto Start]
  <C:\WINDOWS\system32\HPZipm12.exe><HP>
[10moons Remote Control Service / RemoteControlService][Running/Auto Start]
  <C:\Program Files\10Moons\RemoteService\rs.exe><>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
gototop
 

驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Apaidi / Apaidi][Running/Auto Start]
  <\??\C:\WINDOWS\System32\drivers\Apaidi.sys><N/A>
[ati2mtag / ati2mtag][Running/Manual Start]
  <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[%CX23880.video% / CX23880][Running/Auto Start]
  <system32\drivers\cx88vid.sys><Conexant Systems, Inc.>
[10Moons TVBaby3 Crossbar / CX88XBAR][Running/Auto Start]
  <system32\drivers\CX88XBAR.sys><Conexant Systems, Inc.>
[%CXTUNE.DeviceDesc% / CXTUNE][Running/Auto Start]
  <system32\drivers\CX88TUNE.sys><Conexant Systems, Inc.>
[DSDrv4 / DSDrv4][Running/Manual Start]
  <\??\C:\PROGRA~1\10moons\REMOTE~1\DSDrv4.sys><>
[ENTECH / ENTECH][Stopped/Manual Start]
  <\??\C:\WINDOWS\System32\DRIVERS\ENTECH.SYS><EnTech Taiwan>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookSys.sys><Rising>
[IEEE-1284.4 Driver HPZid412 / HPZid412][Stopped/Manual Start]
  <System32\DRIVERS\HPZid412.sys><HP>
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12][Stopped/Manual Start]
  <System32\DRIVERS\HPZipr12.sys><HP>
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12][Stopped/Manual Start]
  <System32\DRIVERS\HPZius12.sys><HP>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
[MCNAHook.SYS / MCNAHook.SYS][Stopped/Auto Start]
  <\??\D:\Program Files\System Safety Monitor\MCNAHook.SYS><N/A>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Padus ASPI Shell / pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[pnpshark / pnpshark][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\pnpshark.sys><>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\PxHelp20.sys><Sonic Solutions>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[TL-WN321G 1.0 USB Wireless Adapter / RT73][Stopped/Manual Start]
  <System32\DRIVERS\rt73.sys><Ralink Technology, Corp.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[Sentinel / Sentinel][Running/Auto Start]
  <\SystemRoot\System32\Drivers\SENTINEL.SYS><>
[SiS163 usb Wireless LAN Adapter Driver / SIS163u][Stopped/Manual Start]
  <System32\DRIVERS\sis163u.sys><N/A>
[SKNFW / SKNFW][Running/System Start]
  <\??\C:\WINDOWS\System32\Drivers\SKNFW.sys><N/A>
[SkyProcs / SkyProcs][Running/Manual Start]
  <\??\D:\PROGRA~1\SkyNet\Firewall\SkyProcs.sys><N/A>
[st3shark / st3shark][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\st3shark.sys><>
[GeneLink File Transfer Driver / USBHSB][Stopped/Auto Start]
  <System32\Drivers\usbhsb.sys><N/A>
[VCD VNC Virtual Network Adapter / vcddev][Stopped/Manual Start]
  <System32\DRIVERS\vcdvnic.sys><VNN B.J.>
[VMware Virtual Ethernet Adapter Driver / VMnetAdapter][Stopped/Manual Start]
  <System32\DRIVERS\vmnetadapter.sys><N/A>
[Virtual PC Application Services / VPCAppSv][Running/Auto Start]
  <System32\DRIVERS\VPCAppSv.sys><Connectix Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter / yukonwxp][Running/Manual Start]
  <System32\DRIVERS\yukonwxp.sys><Marvell Semiconductor Inc.>
[ZSMC USB PC Camera / ZSMC301b][Running/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>
gototop
 

浏览器加载项
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[MSN Photo Upload Tool]
  {4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[portalAXForm Control]
  {6DBED0B2-1FF5-11D8-A26A-0050BA1B2930} <C:\WINDOWS\DOWNLO~1\PortalAX.ocx, >
[PhotoUploadCtrl Control]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <D:\PROGRA~1\Tencent\QQ\QZone\PHOTOU~1.OCX, tencent>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[&使用迅雷下载]
  <D:\Program Files\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\Program Files\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用影音传送带下载]
  <D:\Program Files\NetTransport\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
  <D:\Program Files\NetTransport\NTAddList.html, N/A>
[使用看天下订阅此RSS频道地址]
  <D:\Program Files\Rss\Reader\addlink.htm, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 696][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 756][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 780][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [, ]
    [C:\WINDOWS\system32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 824][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 836][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 992][C:\WINDOWS\System32\Ati2evxx.exe]  [, ]
[PID: 1016][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1652][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1592][C:\WINDOWS\VM_STI.EXE]  [VM., 4.2.610.4]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\WINDOWS\System32\VM31bPrp.Ax]  [VM, 4.2.711.31]
[PID: 1716][C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe]  [FinePrint Software, LLC, 2.42]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppr232.dll]  [FinePrint Software, LLC, 2.42]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppint2.dll]  [FinePrint Software, LLC, 2.42]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppgraf2.dll]  [FinePrint Software, LLC, 2.42]
[PID: 332][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 492][C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll]  [Nero AG, 5,2,1, 8200]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 1, 5, 0, 13]
[PID: 584][C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\NMSQLDB.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Common Files\Ahead\Lib\NMLogCxx.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\log4cxx.dll]  [Nero AG, 1, 0, 0, 0]
    [C:\Program Files\Common Files\Ahead\Lib\NMCoFoundation.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\NMPluginBase.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\NMFullTextExtraction.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\NeroIPP.dll]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  [Nero AG, 1, 5, 0, 13]
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  [Nero AG, 1, 5, 0, 13]
gototop
 

[PID: 1728][C:\Documents and Settings\Fei Xue\桌面\Portal.exe]  [, 3.0.0.0]
[PID: 520][C:\WINDOWS\system32\HPZipm12.exe]  [HP, 10, 1, 1, 2]
[PID: 2668][D:\Program Files\10Moons\TB300\TB300.exe]  [10moons, 2, 1, 0, 0]
    [D:\Program Files\10Moons\TB300\ImageLoad.dll]  [N/A, ]
    [D:\Program Files\10Moons\TB300\TXvidDll.dll]  [10moons, 1, 0, 0, 1]
    [D:\Program Files\10Moons\TB300\RtSmartComm.dll]  [N/A, ]
    [D:\Program Files\10Moons\TB300\DM1105.dll]  [SDMC, 1, 0, 0, 1]
    [D:\Program Files\10Moons\TB300\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.ax]  [, 1.0.2.2017]
    [C:\WINDOWS\System32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [D:\Program Files\K-Lite Codec Pack\filters\divxdec.ax]  [DivX, Inc., 6.2.5.34]
    [D:\Program Files\K-Lite Codec Pack\filters\ac3filter.ax]  [, 1.01a]
    [D:\Program Files\K-Lite Codec Pack\filters\l3codecx.ax]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0311]
    [D:\Program Files\K-Lite Codec Pack\filters\vsfilter.dll]  [Gabest, 1, 0, 1, 3]
    [C:\WINDOWS\System32\wmvadvd.dll]  [Microsoft Corporation, 10.00.00.3646]
    [C:\WINDOWS\System32\mp43dmod.dll]  [Microsoft Corporation, 9.00.00.2980]
    [C:\WINDOWS\System32\acelpdec.ax]  [Sipro Lab Telecom Inc., 1.40]
    [D:\Program Files\K-Lite Codec Pack\filters\vp6dec.ax]  [On2.com Inc., 6,4,2,0]
    [D:\Program Files\K-Lite Codec Pack\filters\CoreVorbis.ax]  [-, 1, 1, 0, 79]
    [D:\Program Files\K-Lite Codec Pack\filters\vp7dec.ax]  [On2.com Inc., 7,0,10,0]
    [C:\Program Files\Common Files\IviSDK\10moons\iviaudio_10moons.ax]  [InterVideo Inc., 4.5.28.80]
    [C:\Program Files\Common Files\IviSDK\10moons\IVIVIDEO_10moons.ax]  [ InterVideo Inc., 4.5.28.80]
    [D:\Program Files\K-Lite Codec Pack\filters\CLVSD.ax]  [CyberLink Corp., 6.0.3402 ]
    [C:\WINDOWS\System32\wmspdmod.dll]  [Microsoft Corporation, 10.00.00.3646]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeBDGraphic.ax]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeBDThumbnail.ax]  [Nero AG, 4,5,9,0]
    [D:\Program Files\K-Lite Codec Pack\filters\MP4Splitter.ax]  [Gabest, 1, 0, 0, 2]
    [D:\Program Files\K-Lite Codec Pack\filters\WavPackDSSplitter.ax]  [-, 1, 0, 3, 277]
    [C:\WINDOWS\System32\RealMediaSplitter.ax]  [Gabest, 1, 0, 1, 0]
    [C:\WINDOWS\System32\mpg2splt.ax]  [, ]
    [D:\Program Files\10Moons\TB300\Filter Packet\mcspmpeg.ax]  [MainConcept AG, 1, 0, 0, 78]
    [D:\Program Files\10Moons\TB300\Filter Packet\mcmpgdec.dll]  [MainConcept AG, official release build]
    [D:\Program Files\K-Lite Codec Pack\filters\illiminable\dsfFLACDecoder.dll]  [N/A, ]
    [D:\Program Files\K-Lite Codec Pack\filters\illiminable\libFLAC++.dll]  [N/A, ]
    [D:\Program Files\K-Lite Codec Pack\filters\illiminable\libFLAC.dll]  [N/A, ]
    [D:\Program Files\K-Lite Codec Pack\filters\illiminable\MSLUR80.dll]  [Sample Corporation, 8.00.0000]
    [D:\Program Files\K-Lite Codec Pack\filters\illiminable\libOOOgg.dll]  [N/A, ]
    [D:\Program Files\K-Lite Codec Pack\filters\illiminable\MSLUP80.dll]  [Sample Corporation, 8.00.0000]
    [D:\Program Files\K-Lite Codec Pack\filters\FLVSplitter.ax]  [Gabest, 1, 0, 0, 1]
    [D:\Program Files\K-Lite Codec Pack\filters\WavPackDSDecoder.ax]  [-, 1, 0, 3, 431]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeMP4Splitter.ax]  [Nero AG, 4,5,9,0]
    [C:\WINDOWS\System32\wmpasf.dll]  [Microsoft Corporation, 10.00.00.3646]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeAudio2.ax]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\DSFilter\msvcp71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll]  [Nero AG, 5,2,1, 8200]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeVideo.ax]  [Nero AG, 4,5,9,0]
    [D:\Program Files\Sonic Foundry\Shared Plug-Ins\File Formats\MCMPEG\mcspmpeg.ax]  [MainConcept GmbH, 1, 0, 0, 30]
    [D:\Program Files\Sonic Foundry\Shared Plug-Ins\File Formats\MCMPEG\mpegin.dll]  [MainConcept AG, prerelease build]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeSplitter.ax]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeVideoHD.ax]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeQTDec.ax]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeOggSplitter.ax]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeSubpicture.ax]  [Nero AG, 4,5,9,0]
    [C:\Program Files\Common Files\Ahead\DSFilter\NeAudio.ax]  [Nero AG, 4,5,9,0]
    [D:\PROGRA~1\10Moons\TB300\filters\Deinterlace.ax]  [10Moons, 1.0.0.0]
[PID: 3768][D:\Program Files\Tencent\TT\TTraveler.exe]  [腾讯公司, 3.2.200.275]
    [D:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  [, 1, 0, 0, 3]
    [D:\Program Files\Tencent\TT\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
    [C:\WINDOWS\System32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5076]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 680][G:\软件\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [hh.exe %1]
.HLP  Error. [C:\WINDOWS\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

又用ICEsword大概看了看,好像没什么问题啊
gototop
 

刚刚更新病毒库,又提示是未知病毒。
是不是瑞星误报哦!!!!!
gototop
 

已经确认,纯属误报
寒一个,还是第一次遇到误报
感情哪天把explorer.exe报成病毒再删掉就安逸了
gototop
 

千千静听4.6.8会报,妈的我也被删除了,结果装个4.6.9就没事,郁闷!
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT