1   1  /  1  页   跳转

中了soundmix.exe

中了soundmix.exe

任务管理器中有soundmix。exe进程,终止后仍然会生成,文件在c:\windows\system32下,使得系统隐藏文件无法显示,该病毒由U盘传入,U盘下有autorun.inf,在U盘的recycler下有autorun.exe。试了对付tel.xls.exe病毒的方法,仍然无效,不知各位有高招不?
另外,用瑞星的疑似扫描,发现有如下疑问,一并问了,谢谢!

未知家族病毒分析
扫描结果:
C:\Program Files\Internet Explorer\IEXPLORE.EXE --> 与 Backdoor.Gpigeon 55%相似.
最后编辑2007-01-11 13:44:48
分享到:
gototop
 

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
d:\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
d:\MATLAB704\webserver\bin\win32\matlabserver.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe
C:\Program Files\UGS\License Servers\UGNXFLEXlm\uglmd.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Huawei-3Com\H3C 802.1X 客户端\Dot1XClient.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\soundmix.exe
C:\progra~1\mcafee\MCAFEE~1\MASCon.exe
c:\program files\mcafee.com\shared\mghtml.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepad.exe
F:\绿色软件\HijackThis1991汉化版\HijackThis1991zww.exe

O1 - Hosts: 61.129.115.198 www.xldd.com
O1 - Hosts: 61.129.115.198 www.ojiang.com
O1 - Hosts: 61.129.115.198 www.shuixian.net
O1 - Hosts: 61.129.115.198 www.xlarea.com
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v8.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - IE工具栏增项: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - IE工具栏增项: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - 启动项HKLM\\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - 启动项HKLM\\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - 启动项HKLM\\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - 启动项HKLM\\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - 启动项HKLM\\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - 启动项HKLM\\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - 启动项HKLM\\Run: [NvCplDaemon] ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [soundmix] C:\WINDOWS\system32\soundmix.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 用比特精灵下载(&B) - C:\Program Files\BitSpirit\bsurl.htm
O8 - IE右键菜单中的新增项目: 转换为 Adobe PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换为现有 PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 转换选定的链接为 Adobe PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - IE右键菜单中的新增项目: 转换选定的链接为现有 PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - IE右键菜单中的新增项目: 转换选项为 Adobe PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换选项为现有 PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 转换链接目标为 Adobe PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换链接目标为现有 PDF - res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -

http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159755871187
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) -

http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2007/OL2006.cab
O18 - 列举现有的协议: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\PROGRA~1\KuGoo3\InExtend\KUGOO3~1.OCX
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - NT 服务: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: Backbone Service (BBDemon) - Unknown owner - d:\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe" -service (file missing)
O23 - NT 服务: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - NT 服务: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - NT 服务: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
O23 - NT 服务: MATLAB Server (matlabserver) - Unknown owner - d:\MATLAB704\webserver\bin\win32\matlabserver.exe
O23 - NT 服务: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - NT 服务: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - NT 服务: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - NT 服务: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - NT 服务: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - NT 服务: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Unigraphics 许可证服务器(uglmd) (Unigraphics License Server (uglmd)) - Macrovision Corporation - C:\Program Files\UGS\License

Servers\UGNXFLEXlm\lmgrd.exe
O23 - NT 服务: Windows System Report Service (winsrs) - Unknown owner - C:\WINDOWS\system32\winsrs.exe
gototop
 

[CODE]

2007-01-11,08:23:42

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}><; "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe">  [Nero AG]
    <EA Core><; C:\Program Files\Electronic Arts\EA Link\Core.exe -silent>  [Electronic Arts]
    <eMuleAutoStart><; C:\Program Files\eMule\emule.exe -AutoStart>  [http://www.emule.org.cn]
    <PcSync><; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <VSOCheckTask><"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask>  [McAfee, Inc.]
    <VirusScan Online><C:\Program Files\McAfee.com\VSO\mcvsshld.exe>  [McAfee, Inc.]
    <OASClnt><C:\Program Files\McAfee.com\VSO\oasclnt.exe>  [McAfee, Inc.]
    <MCAgentExe><c:\PROGRA~1\mcafee.com\agent\mcagent.exe>  [McAfee, Inc]
    <MCUpdateExe><c:\PROGRA~1\mcafee.com\agent\mcupdate.exe>  [McAfee, Inc]
    <MPFExe><C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe>  [(Verified)McAfee Security]
    <_AntiSpyware><c:\progra~1\mcafee\MCAFEE~1\masalert.exe>  [McAfee, Inc.]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)NVIDIA Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\Flurry.scr>  [Matt Ginzton]

==================================
启动文件夹
N/A

==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[Backbone Service / BBDemon][Running/Auto Start]
  <"d:\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe" -service><Dassault Systemes>
[Crypkey License / Crypkey License][Running/Auto Start]
  <crypserv.exe><Kenonic Controls Ltd.>
[Hummingbird Inetd / HCLInetd][Running/Auto Start]
  <C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe><Hummingbird Ltd.>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Hummingbird Jconfig Daemon / Jconfigd][Running/Auto Start]
  <C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe><Hummingbird Ltd.>
[MATLAB Server / matlabserver][Running/Auto Start]
  <d:\MATLAB704\webserver\bin\win32\matlabserver.exe><N/A>
[McAfee AntiSpyware Service / McAfee AntiSpyware Service][Running/Auto Start]
  <"c:\progra~1\mcafee\mcafee antispyware\massrv.exe"><McAfee, Inc.>
[McAfee WSC Integration / McDetect.exe][Running/Auto Start]
  <c:\program files\mcafee.com\agent\mcdetect.exe><McAfee, Inc>
[McAfee.com McShield / McShield][Running/Auto Start]
  <c:\PROGRA~1\mcafee.com\vso\mcshield.exe><McAfee Inc.>
[McAfee Task Scheduler / McTskshd.exe][Running/Auto Start]
  <c:\PROGRA~1\mcafee.com\agent\mctskshd.exe><McAfee, Inc>
[McAfee SecurityCenter Update Manager / mcupdmgr.exe][Stopped/Manual Start]
  <C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe><McAfee, Inc>
[McAfee Personal Firewall Service / MpfService][Running/Auto Start]
  <C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe><McAfee Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Unigraphics 许可证服务器(uglmd) / Unigraphics License Server (uglmd)][Running/Auto Start]
  <"C:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe"><Macrovision Corporation>
[Windows System Report Service / winsrs][Stopped/Auto Start]
  <C:\WINDOWS\system32\winsrs.exe><N/A>
gototop
 

驱动程序
[dump_wmimmc / dump_wmimmc][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\dump_wmimmc.sys><N/A>
[ECTIVA Audio 5.1 (WDM) / ECTIVA][Running/Manual Start]
  <system32\drivers\ECTIVA.sys><Creative Technology Ltd.>
[ElbyCDIO Driver / ElbyCDIO][Running/Auto Start]
  <System32\Drivers\ElbyCDIO.sys><Elaborate Bytes AG>
[ElbyDelay / ElbyDelay][Running/Manual Start]
  <System32\Drivers\ElbyDelay.sys><Elaborate Bytes AG>
[InCD File System / InCDFs][Stopped/Disabled]
  <system32\drivers\InCDFs.sys><N/A>
[InCDPass / InCDPass][Stopped/System Start]
  <system32\drivers\InCDPass.sys><N/A>
[InCD Reader / InCDRm][Stopped/System Start]
  <system32\drivers\InCDRm.sys><N/A>
[Logitech SetPoint HID Mouse Filter Driver / LHidKe][Running/Manual Start]
  <system32\DRIVERS\LHidKE.Sys><Logitech, Inc.>
[Logitech SetPoint USB Receiver device driver / LHidUsbK][Running/Manual Start]
  <System32\Drivers\LHidUsbK.Sys><Logitech, Inc.>
[Logitech SetPoint Mouse Filter Driver / LMouKE][Running/Manual Start]
  <system32\DRIVERS\LMouKE.Sys><Logitech, Inc.>
[LUMDriver / LUMDriver][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\LUMDriver.sys><IBM>
[MPFIREWL / MPFIREWL][Running/System Start]
  <System32\Drivers\MpFirewall.sys><McAfee>
[NaiAvFilter1 / NaiAvFilter1][Running/Manual Start]
  <system32\drivers\naiavf5x.sys><McAfee Inc.>
[NetworkX / NetworkX][Running/System Start]
  <\SystemRoot\system32\ckldrv.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkcusb / npkcusb][Running/Manual Start]
  <\??\C:\Program Files\Tencent\QQ\npkcusb.sys><INCA Internet Co., Ltd.>
[NPPTNT2 / NPPTNT2][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npptNT2.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PCAMPR5 NDIS Protocol Driver / PCAMPR5][Running/Manual Start]
  <\??\C:\WINDOWS\system32\PCAMPR5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
[PCANDIS5 NDIS Protocol Driver / PCANDIS5][Running/Manual Start]
  <\??\C:\WINDOWS\system32\PCANDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
[Padus ASPI Shell / pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Sentinel / Sentinel][Running/Auto Start]
  <\SystemRoot\System32\Drivers\SENTINEL.SYS><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[USB to Serial Bridge Controller / usb2vcom][Stopped/Manual Start]
  <system32\DRIVERS\usb2vcom.sys><Ark Pioneer Microelectronics Ltd.>
[VClone / VClone][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\VClone.sys><Elaborate Bytes AG>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[videX32 / videX32][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\videX32.sys><VIA Technologies, Inc.>
[VIA USB Host Controller Lower Filter / vulfnths][Running/Manual Start]
  <\SystemRoot\System32\Drivers\vulfnth.sys><VIA Technologies, Inc.>
[VIA USB Roothub Lower Filter / vulfntrs][Running/Manual Start]
  <\SystemRoot\System32\Drivers\vulfntr.sys><VIA Technologies, Inc.>
[WINIO / WINIO][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\winio.sys><N/A>
[xFileMgr / xFileMgr][Running/System Start]
  <\??\C:\WINDOWS\system32\Drivers\xFileMgr.sys><MS User>
[VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
[NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start]
  <system32\DRIVERS\yk51x86.sys><Marvell>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484f-8273-0445EE161910} <D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[McAfee VirusScan]
  {BA52B914-B692-46c4-B683-905236F6F655} <c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[MMCPlayer Class]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[McAfee.com Operating System Class]
  {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} <C:\WINDOWS\system32\mcinsctl.dll, McAfee, Inc>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[ActiveMovieControl Object]
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MMCPlayer Class]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[IETag Factory]
  {38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484F-8273-0445EE161910} <D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[McAfee VirusScan]
  {BA52B914-B692-46C4-B683-905236F6F655} <c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\system\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
  <C:\Program Files\BitSpirit\bsurl.htm, N/A>
[转换为 Adobe PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换为现有 PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换选定的链接为 Adobe PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
[转换选定的链接为现有 PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
[转换选项为 Adobe PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换选项为现有 PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换链接目标为 Adobe PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换链接目标为现有 PDF]
  <res://D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
gototop
 

正在运行的进程
[PID: 700][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 824][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 836][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1072][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1168][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1212][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1268][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1532][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\AdobePDF.dll]  [Adobe Systems Incorporated., 7.0.0.00]
    [D:\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS]  [N/A, N/A]
    [C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Accessories\hcllpr.dll]  [Hummingbird Ltd., 7.1.0.0]
    [C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Accessories\hcllpr.nls]  [Hummingbird Ltd., 7.1.0.0]
[PID: 1748][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.2.54.0]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
    [D:\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 7.0.0.0]
    [D:\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs]  [Adobe Systems Inc., 7.0.0.2004121400\0]
    [C:\WINDOWS\system32\mp3infp.dll]  [win32lab.com, 2.50.5.0]
    [D:\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9147]
    [C:\WINDOWS\system32\nvapi.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\nvshell.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\xunleibho_v8.dll]  [, 4, 5, 1, 33]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Hummingbird\Connectivity\7.10\HostExplorer\Ftp\heshell.dll]  [Hummingbird Ltd., 7.1.0.0]
[PID: 1912][C:\Program Files\McAfee.com\VSO\mcvsshld.exe]  [McAfee, Inc., 10, 0, 0, 22]
    [C:\Program Files\McAfee.com\VSO\VsCfgW32.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [C:\Program Files\McAfee.com\VSO\ashldres.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll]  [McAfee, Inc, 6, 0, 0, 15]
    [c:\program files\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc, 5, 0, 0, 0]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\progra~1\mcafee.com\vso\mcvsps.dll]  [McAfee, Inc, 10, 0, 0, 17]
[PID: 1940][C:\Program Files\McAfee.com\VSO\oasclnt.exe]  [McAfee, Inc., 10, 0, 0, 24]
    [c:\program files\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc, 5, 0, 0, 0]
    [c:\progra~1\mcafee.com\vso\naiannps.dll]  [McAfee, Inc, 10, 0, 0, 0]
    [c:\progra~1\mcafee.com\vso\mcvsps.dll]  [McAfee, Inc, 10, 0, 0, 17]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
[PID: 1984][C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe]  [McAfee Security, 7.1.0.113]
    [C:\PROGRA~1\McAfee.com\PERSON~1\Localized.DLL]  [McAfee Security, 7.1.0.113]
    [C:\WINDOWS\system32\MPFAPI.dll]  [McAfee, 7.1.0.113]
    [c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll]  [McAfee, Inc, 6, 0, 0, 15]
    [c:\program files\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc, 5, 0, 0, 0]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
[PID: 1992][C:\progra~1\mcafee\MCAFEE~1\masalert.exe]  [McAfee, Inc., 2.1.0.112]
    [C:\progra~1\mcafee\MCAFEE~1\MASRes.dll]  [McAfee, Inc., 2.1.0.115]
    [c:\program files\mcafee.com\agent\McUILib.DLL]  [McAfee, Inc, 6, 0, 0, 5]
    [c:\progra~1\mcafee\mcafee antispyware\massrvps.dll]  [McAfee, Inc., 2.1.0.112]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
[PID: 2004][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
[PID: 2020][c:\progra~1\mcafee.com\vso\mcvsescn.exe]  [McAfee, Inc., 10, 0, 0, 20]
    [c:\progra~1\mcafee.com\vso\ashldres.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\progra~1\mcafee.com\vso\EmScnRes.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\PROGRA~1\mcafee.com\vso\vsoupd.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\progra~1\mcafee.com\vso\McVsWorm.dll]  [McAfee, Inc., 10, 0, 0, 19]
    [C:\Program Files\McAfee.com\VSO\VsCfgW32.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\progra~1\mcafee.com\vso\WormRes.dll]  [McAfee, Inc., 10, 0, 0, 19]
    [c:\program files\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc, 5, 0, 0, 0]
[PID: 1372][d:\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe]  [Dassault Systemes, 5.16.1.5278]
[PID: 1448][C:\WINDOWS\system32\crypserv.exe]  [Kenonic Controls Ltd., 5.4.0]
[PID: 1612][C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe]  [Hummingbird Ltd., 7.1.0.0]
    [C:\WINDOWS\system32\HCLNLS.dll]  [Hummingbird Ltd., 7.1.0.0]
    [C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\humprdin.dll]  [Hummingbird Ltd., 7.1.0.0]
    [C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\HCINETD.NLS]  [Hummingbird Ltd., 7.1.0.0]
[PID: 1744][C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe]  [Hummingbird Ltd., 7.1.0.0]
[PID: 1456][d:\MATLAB704\webserver\bin\win32\matlabserver.exe]  [N/A, N/A]
    [d:\MATLAB704\bin\win32\libeng.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\MATLAB704\bin\win32\libut.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\MATLAB704\bin\win32\icuuc24.dll]  [IBM Corporation and others, 2, 4, 0, 0]
    [d:\MATLAB704\bin\win32\icudt24l.dll]  [N/A, N/A]
    [d:\MATLAB704\bin\win32\icuin24.dll]  [IBM Corporation and others, 2, 4, 0, 0]
    [d:\MATLAB704\bin\win32\icuio24.dll]  [IBM Corporation and others, 2, 4, 0, 0]
    [d:\MATLAB704\bin\win32\libmx.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\MATLAB704\bin\win32\zlib1.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\mwoles05.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\bridge.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\udd_mi.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\mvalue.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmwgui.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmwservices.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\mpath.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\m_interpreter.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\xerces-c_2_1_0.dll]  [Apache Software Foundation, 2, 1, 0]
    [d:\matlab704\bin\win32\mcos.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_dispatcher.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\datasvcs.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_pcodeio.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\mlib.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_ir.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmex.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\matlab704\bin\win32\m_pcodegen.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_parser.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\ir_xfmr.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmat.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\matlab704\bin\win32\udd.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\jmi.dll]  [The MathWorks Inc., 7.0.2.26013]
    [d:\matlab704\bin\win32\comcli.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\uiw.dll]  [The MathWorks Inc., 7.0.0.18578]
    [d:\matlab704\bin\win32\uinone.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmwhardcopy.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libuij.dll]  [N/A, N/A]
[PID: 1900][c:\progra~1\mcafee\mcafee antispyware\massrv.exe]  [McAfee, Inc., 2.1.0.112]
    [c:\progra~1\mcafee\mcafee antispyware\mytilus2.dll]  [McAfee, Inc., 12.0.0.266]
    [c:\progra~1\mcafee\mcafee antispyware\mytilus.dll]  [McAfee, Inc., 12.0.0.266]
    [c:\progra~1\mcafee\mcafee antispyware\McShield.dll]  [McAfee, Inc., 12.0.0.266]
    [c:\progra~1\mcafee\mcafee antispyware\mcscan32.dll]  [McAfee, Inc., 5.0.00]
    [c:\progra~1\mcafee\mcafee antispyware\massrvps.dll]  [McAfee, Inc., 2.1.0.112]
    [c:\progra~1\mcafee\mcafee antispyware\wmimon.dll]  [McAfee, Inc., 2.1.0.112]
    [c:\progra~1\mcafee\mcafee antispyware\pollmon.dll]  [McAfee, Inc., 2.1.0.112]
gototop
 

[PID: 1956][d:\matlab704\bin\win32\matlab.exe]  [The MathWorks Inc., 7.0.2.26397]
    [d:\matlab704\bin\win32\mvalue.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libut.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\matlab704\bin\win32\icuuc24.dll]  [IBM Corporation and others, 2, 4, 0, 0]
    [d:\matlab704\bin\win32\icudt24l.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\icuin24.dll]  [IBM Corporation and others, 2, 4, 0, 0]
    [d:\matlab704\bin\win32\icuio24.dll]  [IBM Corporation and others, 2, 4, 0, 0]
    [d:\matlab704\bin\win32\libmx.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\matlab704\bin\win32\zlib1.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmwservices.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\mpath.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\libmex.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\matlab704\bin\win32\m_dispatcher.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\xerces-c_2_1_0.dll]  [Apache Software Foundation, 2, 1, 0]
    [d:\matlab704\bin\win32\datasvcs.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\mcr.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\bridge.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\udd_mi.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\libmwgui.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_interpreter.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\mcos.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_pcodeio.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\mlib.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_ir.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_pcodegen.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\m_parser.dll]  [The MathWorks Inc., 7.0.2.26049]
    [d:\matlab704\bin\win32\ir_xfmr.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmat.dll]  [The MathWorks Inc., 7.0.0.12365]
    [d:\matlab704\bin\win32\udd.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\jmi.dll]  [The MathWorks Inc., 7.0.2.26013]
    [d:\matlab704\bin\win32\mlautoregister.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\hg.dll]  [The MathWorks Inc., 7.0.2.26013]
    [d:\matlab704\bin\win32\uiw.dll]  [The MathWorks Inc., 7.0.0.18578]
    [d:\matlab704\bin\win32\uinone.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmwhardcopy.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libuij.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\numerics.dll]  [The MathWorks Inc., 7.0.2.26081]
    [d:\matlab704\bin\win32\libmwamd.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libfftw3.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libfftw3f.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmwlapack.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\libmwumfpackv4.3.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\mwoles05.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\comcli.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\atlas_Athlon.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\lapack.dll]  [N/A, N/A]
    [d:\matlab704\bin\win32\DFORRT.DLL]  [Compaq Computer Corporation, 6.6 - 893 (Update A)]
    [d:\matlab704\sys\java\jre\win32\jre1.5.0\bin\client\jvm.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [d:\matlab704\sys\java\jre\win32\jre1.5.0\bin\hpi.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [d:\matlab704\sys\java\jre\win32\jre1.5.0\bin\verify.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [d:\matlab704\sys\java\jre\win32\jre1.5.0\bin\java.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [d:\matlab704\sys\java\jre\win32\jre1.5.0\bin\zip.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [d:\matlab704\bin\win32\jmi_mi.dll]  [N/A, N/A]
    [D:\MATLAB704\sys\java\jre\win32\jre1.5.0\bin\awt.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [D:\MATLAB704\bin\win32\nativejava.dll]  [N/A, N/A]
    [D:\MATLAB704\sys\java\jre\win32\jre1.5.0\bin\fontmanager.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [D:\MATLAB704\sys\java\jre\win32\jre1.5.0\bin\net.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [D:\MATLAB704\sys\java\jre\win32\jre1.5.0\bin\nio.dll]  [Sun Microsystems, Inc., 1.5.0.0]
    [d:\matlab704\bin\win32\libmwbuiltins.dll]  [The MathWorks Inc., 7.0.0.12365]
[PID: 1976][c:\program files\mcafee.com\agent\mcdetect.exe]  [McAfee, Inc, 6, 0, 0, 19]
[PID: 2028][c:\PROGRA~1\mcafee.com\vso\mcshield.exe]  [McAfee Inc., 11.0.0.151]
    [c:\PROGRA~1\mcafee.com\vso\RES00\McShield.DLL]  [McAfee Inc., 11.0.0.141]
    [c:\PROGRA~1\mcafee.com\vso\FTL.Dll]  [McAfee Inc., 11.0.0.151]
    [c:\PROGRA~1\mcafee.com\vso\naiann.dll]  [McAfee, Inc., 10, 0, 0, 21]
    [c:\PROGRA~1\mcafee.com\vso\mytilus.dll]  [McAfee Inc., 11.0.0.151]
    [C:\Program Files\McAfee.com\VSO\MCSCAN32.DLL]  [McAfee, Inc., 5.1.00]
    [c:\program files\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc, 5, 0, 0, 0]
    [c:\progra~1\mcafee.com\vso\naiannps.dll]  [McAfee, Inc, 10, 0, 0, 0]
[PID: 228][c:\PROGRA~1\mcafee.com\agent\mctskshd.exe]  [McAfee, Inc, 6, 0, 0, 13]
[PID: 600][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 616][C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe]  [McAfee Corporation, 7.1.0.113]
    [C:\WINDOWS\system32\MPFAPI.dll]  [McAfee, 7.1.0.113]
[PID: 656][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.9147]
    [C:\WINDOWS\system32\nvapi.dll]  [N/A, N/A]
[PID: 388][C:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe]  [Macrovision Corporation, 9, 2, 2, 0]
[PID: 276][C:\Program Files\UGS\License Servers\UGNXFLEXlm\uglmd.exe]  [N/A, N/A]
[PID: 2304][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3112][C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe]  [McAfee Security, 7.1.0.113]
    [C:\PROGRA~1\McAfee.com\PERSON~1\Localized.DLL]  [McAfee Security, 7.1.0.113]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [c:\program files\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc, 5, 0, 0, 0]
[PID: 3460][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3772][C:\Program Files\Huawei-3Com\H3C 802.1X 客户端\Dot1XClient.exe]  [N/A, N/A]
    [C:\WINDOWS\system32\W32N50.dll]  [Printing Communications Assoc., Inc. (PCAUSA), 5.03.16.56]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
[PID: 3056][C:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 14]
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2005, 9, 1, 1]
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\SCCore.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 0, 3, 3, 8]
    [C:\Program Files\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll]  [tencent, 0, 2, 2, 3]
    [C:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 141]
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 3, 30]
    [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, N/A]
[PID: 1768][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 2592][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
[PID: 2188][C:\WINDOWS\system32\soundmix.exe]  [N/A, N/A]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
[PID: 2176][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]
    [D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll]  [Adobe Systems Incorporated, 7.0.0.0]
    [D:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.CHS]  [Adobe Systems Incorporated, 7.0.0.0]
    [c:\program files\google\googletoolbar2.dll]  [Google Inc., 4, 0, 1020, 3054]
    [C:\WINDOWS\system32\xunleibho_v8.dll]  [, 4, 5, 1, 33]
    [D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
    [C:\Program Files\Tencent\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [D:\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\Macromed\Common\SwSupport.dll]  [Macromedia, Inc., 10.1r11]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.2.54.0]
[PID: 1028][F:\绿色软件\新建文件夹\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [c:\progra~1\mcafee.com\vso\McVSSkt.dll]  [McAfee, Inc., 10, 0, 0, 26]
    [F:\绿色软件\新建文件夹\Plugins\SRECXTMG.SRE]  [Smallfrogs Studio, 1, 5, 0, 55]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  Error. [soundmix "%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
61.129.115.198 www.xldd.com
61.129.115.198 www.ojiang.com
61.129.115.198 www.shuixian.net
61.129.115.198 www.xlarea.com
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

现在又发现有新的症状,在安全模式下用瑞星或者毒霸查毒,能找到病毒,并且成功清除,提示重新启动,然而,重启后,无法识别exe文件,总是弹出选择打开方式的对话框
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT