瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 这是些什么病毒啊???怎么杀也杀不完哪!_!

1   1  /  1  页   跳转

这是些什么病毒啊???怎么杀也杀不完哪!_!

这是些什么病毒啊???怎么杀也杀不完哪!_!

版本:18.23.30
病毒名称                        处理结果    发现日期         
Rootkit.Vanti.gen              删除成功    2006-04-20 11:00 
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:10 
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:46 
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:46 
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:47 
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:47
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:47
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:47
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:48
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:48
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:48
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:48
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:48
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:49
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:49
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 10:50
JS.CodeExec.a                  清除成功    2006-04-22 11:02
Hack.Exploit.Realplayer.a      删除成功    2006-04-22 11:02
Backdoor.Gpigeon.ypv            重新启动计算机后删除文件2006-04-22 11:12 
Backdoor.Gpigeon.yjz            重新启动计算机后删除文件2006-04-22 11:12
Backdoor.Gpigeon.ypv            删除成功    2006-04-22 14:17
Backdoor.Gpigeon.yjz            删除成功    2006-04-22 14:18
Worm.SpyBot.yu                  删除成功    2006-04-22 14:26
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 22:57
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 22:58
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 22:58
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 22:58
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 22:59
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 22:59
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 22:59
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:20
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:22
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:24
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:25
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:26
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:26
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:27
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:27
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:27
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:27
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:27
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-22 23:28
Backdoor.Gpigeon.ypv            重新启动计算机后删除文件2006-04-22 23:58 
Backdoor.Gpigeon.yjz            重新启动计算机后删除文件2006-04-22 23:58 
Backdoor.Gpigeon.yjz            重新启动计算机后删除文件2006-04-23 00:02 
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:43     
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:43     
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:43     
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:43     
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:44     
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:44     
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:44     
Backdoor.Gpigeon.2006.bm        清除成功    2006-04-23 15:44     
Backdoor.Gpigeon.ypv            重新启动计算机后删除文件2006-04-23 15:49   
Backdoor.Gpigeon.yjz            重新启动计算机后删除文件2006-04-23 15:50 

经常死机,杀毒重启一会儿又死,再杀又是这些,重启又杀还是这些~
怎么办哪???我不想重装系统了~
 
最后编辑2006-04-27 14:17:00
分享到:
gototop
 

文件名和路径
Backdoor.Gpigeon.2006.bmwinlogon.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmnvsvc32.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmMSTask.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmIEXPLORE.EXE>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmExplorer.EXE>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmrealsched.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmMixer.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmwinlogon.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmnvsvc32.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmMSTask.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmIEXPLORE.EXE>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmExplorer.EXE>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmrealsched.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmMixer.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmctfmon.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmwnwb.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmewido.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmconime.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.2006.bmSecuritySuite.exe>>C:\WINNT\svchootKey.DLL本机
Backdoor.Gpigeon.ypvC:\WINNTsvchoot.DLL本机
Backdoor.Gpigeon.yjzC:\WINNTsvchootKey.DLL本机
安全模式下也杀过了,没有这些病毒
gototop
 

006-04-23,17:41:25

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows 2000 Professional Service Pack 4 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <Synchronization Manager><mobsync.exe /logon>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvCplDaemon><; RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <nwiz><; nwiz.exe /install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvMediaCenter><; RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <C-Media Mixer><Mixer.exe /startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NeroFilterCheck><; C:\WINNT\system32\NeroCheck.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"D:\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINNT\system32\userinit.exe,C:\WINNT\system32\SVCH0ST.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
服务
[Dlerter / Dlerter]
  <><N/A>
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINNT\system32\nvsvc32.exe><NVIDIA Corporation>
[PPPoE Service / PPPoEService]
  <C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe><N/A>
[Rising Process Communication Center / RsCCenter]
  <"D:\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"D:\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[MSIServers / Windows Instaler]
  <C:\WINNT\svchoot.exe><N/A>

==================================
浏览器加载项
[bho Class]
  {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} <C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll, 深圳世强软件开发部>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\FLASHGET\flashget.exe, Amaze Soft>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\FLASHGET\fgiebar.dll, Amaze Soft>
[CyberArticle Express]
  {769A6A36-ED24-4376-BC7C-80225BF35698} <, N/A>
[Shockwave ActiveX Control]
  {166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINNT\system32\macromed\Shockwave 10\Download.dll, Macromedia, Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[使用网际快车下载]
  <D:\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <D:\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Excel(&x)]
  <res://D:\MICROS~1\Office10\EXCEL.EXE/3000, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>

==================================
正在运行的进程
[PID: 144][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 168][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 188][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.6997>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 216][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.7035>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.6605.297.3>
[PID: 228][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.7011>
[PID: 388][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 416][D:\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 432][D:\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [D:\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [D:\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [D:\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [D:\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [D:\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [D:\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [D:\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [D:\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [D:\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [D:\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [D:\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [D:\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [D:\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [D:\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 476][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2195.7059>
    [C:\WINNT\system32\E_SL2302.DLL]  <SEIKO EPSON CORPORATION><2, 12, 0, 0>
    [C:\WINNT\system32\EBPMON2.DLL]  <SEIKO EPSON CORPORATION><2, 16, 0, 0>
[PID: 508][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 544][C:\WINNT\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.6766>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
gototop
 

[PID: 588][C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe]  <N/A><N/A>
[PID: 604][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.6972>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 720][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0100>
[PID: 756][D:\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [D:\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 776][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 908][C:\WINNT\Explorer.EXE]  <Microsoft Corporation><5.00.3700.6690>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINNT\system32\mprmsgs.dll]  <N/A><N/A>
    [D:\读图程序\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\WINNT\system32\mq1pgmgr.dll]  <N/A><N/A>
    [D:\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [D:\wnwb2005\WNMKEY.DLL]  <深圳世强软件开发部 www.wnwb.com ><2005, 7, 5, 1>
    [C:\WINNT\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [D:\WinRAR\rarext.dll]  <N/A><N/A>
[PID: 1052][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3208>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 1060][C:\WINNT\Mixer.exe]  <C-Media Electronic Inc. (www.cmedia.com.tw)><1.58>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
    [C:\WINNT\System32\cmnprop.dll]  <C-Media Corporation><5.00.2195.12>
[PID: 1084][D:\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [D:\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 1088][C:\WINNT\system32\ctfmon.exe]  <Microsoft Corporation><1.00.2409.34 built by: Lab06_N>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 1116][D:\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 17>
    [D:\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [D:\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 348][C:\PROGRA~1\EFFICI~1\ENTERN~1\app\EnterNet.exe]  <N/A><N/A>
    [C:\PROGRA~1\EFFICI~1\ENTERN~1\app\PacketLog.dll]  <Efficient Networks, Inc.><1, 5, 0, 21>
    [C:\PROGRA~1\EFFICI~1\ENTERN~1\app\DSLAPI32.dll]  <Efficient Networks Inc.><1, 5, 0, 19>
    [C:\PROGRA~1\EFFICI~1\ENTERN~1\app\ResMsgENU.dll]  <Efficient Networks, Inc.><1, 5, 0, 18>
    [C:\PROGRA~1\EFFICI~1\ENTERN~1\app\ResENU.dll]  <Efficient Networks, Inc.><1, 5, 0, 18>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 1368][C:\WINNT\system32\conime.exe]  <Microsoft Corporation><5.00.2195.6655>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 964][E:\security suite\security suite\ewido.exe]  <N/A><N/A>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 1484][E:\security suite\security suite\SecuritySuite.exe]  <ewido networks><3, 5, 0, 0>
    [E:\security suite\security suite\lang.dll]  <privat><1, 0, 0, 1>
    [E:\security suite\security suite\wizard.dll]  <N/A><N/A>
    [E:\security suite\security suite\framework.dll]  <ewido networks><1, 0, 0, 249>
    [E:\security suite\security suite\configuration.dll]  <ewido networks><1, 0, 0, 1>
    [E:\security suite\security suite\engine.dll]  <ewido networks GmbH & Co. KG><4, 0, 0, 2>
    [E:\security suite\security suite\scan.dll]  <ewido networks><1, 0, 0, 2>
    [E:\security suite\security suite\modules\autostartviewer.dll]  <ewido networks><1, 0, 0, 114>
    [E:\security suite\security suite\TScan1.dll]  <ewido networks><3, 0, 0, 0>
    [E:\security suite\security suite\archive.dll]  <N/A><N/A>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
    [E:\security suite\security suite\modules\connectionwatch.dll]  <ewido networks><1, 0, 0, 2>
    [E:\security suite\security suite\modules\processviewer.dll]  <privat><1, 0, 0, 2>
    [E:\security suite\security suite\quarantine.dll]  <ewido networks><1, 0, 0, 43>
    [E:\security suite\security suite\update.dll]  <ewido networks><1, 0, 0, 8>
    [E:\security suite\security suite\update_core.dll]  <N/A><N/A>
    [E:\security suite\security suite\info.dll]  <ewido networks><1, 0, 0, 137>
    [E:\security suite\security suite\resources.dll]  <N/A><N/A>
[PID: 1460][D:\wnwb2005\wnwb.exe]  <深圳世强软件开发部 www.wnwb.com ><2005, 11, 19, 1>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
    [D:\wnwb2005\WNMKEY.DLL]  <深圳世强软件开发部 www.wnwb.com ><2005, 7, 5, 1>
[PID: 1544][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
    [C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll]  <深圳世强软件开发部><2005, 8, 30, 1>
    [D:\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [D:\wnwb2005\WNMKEY.DLL]  <深圳世强软件开发部 www.wnwb.com ><2005, 7, 5, 1>
    [C:\WINNT\system32\mq1pgmgr.dll]  <N/A><N/A>
    [C:\WINNT\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 5764][E:\eMule\eMule.exe]  <http://www.emule.org.cn><0.46.2>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
    [E:\eMule\lang\zh_CN.dll]  <http://www.emule-project.net><0.46.2>
[PID: 13792][D:\Rav\Rav.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 61>
    [D:\Rav\PlugIn\RsPgScan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
    [D:\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rav\RavUI.Dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 57>
    [D:\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [D:\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
    [D:\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [D:\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\Rav\RavUIMsg.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\WINNT\system32\mq1pgmgr.dll]  <N/A><N/A>
    [D:\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 14128][C:\Documents and Settings\Administrator\桌面\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>
[PID: 14540][D:\Rav\Smartup.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 64>
    [D:\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [D:\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINNT\svchootKey.DLL]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

就是在百度查“Alt WAV MP3 WMA OGG Converter 注册码”的时候上了个网页就中毒了
gototop
 

!0!
不是吧
这么惨~

看来只好重装系统了~
所以说好多网页是不能乱上得~
gototop
 

好吧好吧
谁叫我是第一个中毒得
gototop
 

找了半天只找到svchootKey.txt
等我又重启一次看看
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT