1   1  /  1  页   跳转

Trojan.PSW.QQGame.v删不掉

Trojan.PSW.QQGame.v删不掉

瑞星杀不掉 安全模式里也查不出来
每次电脑启动后 瑞星就查出来了 但不能彻底删除

附件附件:

下载次数:216
文件类型:image/pjpeg
文件大小:
上传时间:2006-8-15 17:19:15
描述:



最后编辑2006-08-16 12:57:27
分享到:
gototop
 

怎么给你看日志?报告太长发不上来
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <nwiz><nwiz.exe /install>  [NVIDIA Corporation]
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [NVIDIA Corporation]
    <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  []
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <RavTask><"C:\Program Files\瑞星\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <!ewido><"C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized>  [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <CheckFaultKernel><C:\WINDOWS\system32\mswdm.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe>  [Microsoft Corporation]
    <UIHost><"\Program Files\Logonui\Royale.exe">  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{10104C5C-5252-435F-AE90-45335A260A88}><C:\WINDOWS\system32\Mwpush.dll>  []
    <{A9FE5BB8-C832-4F71-B63E-A48EF21768B9}><C:\WINDOWS\system32\Nimr.dll>  []
    <{21F0B3DA-3CFD-4B12-A7B9-B6F8E66CC5D3}><C:\WINDOWS\system32\Vzpm.dll>  []
    <{778419EF-9DE3-47DF-958E-E71A9E7F2BC8}><C:\WINDOWS\system32\Ncbj.dll>  []
    <{16B85A80-976F-40FB-89A7-E380662C56AA}><C:\WINDOWS\system32\Gdcz.dll>  []
    <{2970665C-B2B2-4A49-B10F-722C574E2E45}><C:\WINDOWS\system32\Xahs.dll>  []
    <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll>  [Anti-Malware Development a.s.]
gototop
 

==================================
启动文件夹
服务
[DNS Cache / BARCASE]
  <C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
  <C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\瑞星\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\瑞星\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SymWMI Service / SymWSC]
  <"C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"><Symantec Corporation>
[Print Controller / Universal Disk Manager]
  <C:\Program Files\Common Files\SAND\client.exe><N/A>
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT