1   1  /  1  页   跳转

是Sreng日志.求助啊!

是Sreng日志.求助啊!

电脑中病毒了,自动弹出对话框说发现病毒,一直弹,即使用GHOST备分还原成原来的系统还是这样,最后完全重装新的系统还是这样,怎么回师啊?
现在是一会一会就弹出对话框,发现的病毒有比如:C:\WINDOWS\System32\msccrt.dll

附件附件:

下载次数:177
文件类型:application/octet-stream
文件大小:
上传时间:2007-10-8 23:11:21
描述:

最后编辑2007-10-11 00:46:11.123000000
分享到:
gototop
 

我按着你的指示做了,但下面这些不能被选入(显示为:不存在该文件(软件不支持删除文件夹)):
C:\WINDOWS\System32\cmicnfg.cpl
C:\WINDOWS\System32\CMICtrlWnd
C:\WINDOWS\gviaul.exe
C:\WINDOWS\NVDispDrv.exe
C:\WINDOWS\mpcdxh.exe
C:\WINDOWS\IGM.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\System32\LYLeador.exe
C:\WINDOWS\System32\winforms.dll
但我依然按指示,把其他能删的都删了,然后一步步做下去,但最后重启了还是会弹出框说有病毒,还是那些病毒
gototop
 

我查了下,病毒差不多有如下几种:

威胁: Infostealer.Gampass
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\652LPS8Z\mh0618[1].exe

威胁: Trojan.PWS.QQPass
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\N99SKD1Q\dh0616[1].exe

威胁: Infostealer.Gampass
文件:  C:\Documents and Settings\EADING\Local Settings\Teporary Internet Files\Content.IE5\W3ENC3QJ\dh3[1].exe

威胁: Infostealer
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\W3ENC3QJ\wm[1].exe

威胁: Infostealer.Gampass
文件:  C:\Documents and Settings\EADING\Local Settings\Temporary Internet Files\Content.IE5\N99SKD1Q\dh3[1].exe
gototop
 

[CODE]

2007-10-09,20:31:54

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Windows XP Publisher]
    <MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <IgfxTray><C:\WINDOWS\System32\igfxtray.exe>  [(Verified)Microsoft Windows XP Publisher]
    <HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd>  [N/A]
    <STDSB><C:\WINDOWS\System32\STDSB.exe>  [N/A]
    <SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>  [(Verified)Microsoft Windows XP Publisher]
    <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Microsoft Windows XP Publisher]
    <D-Link AirPlus G><C:\Program Files\D-Link\AirPlus G\AirGCFG.exe>  [D-Link]
    <ANIWZCS2Service><C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe>  [Alpha Networks Inc.]
    <ZSSnp211><C:\WINDOWS\ZSSnp211.exe>  [ZSMCSNAP]
    <Domino><C:\WINDOWS\Domino.exe>  []
    <GenProtect><C:\WINDOWS\GenProtect.exe>  []
    <AVPSrv><C:\WINDOWS\AVPSrv.exe>  []
    <NVDispDrv><C:\WINDOWS\nqvrgy.exe>  []
    <MsPrint32D><C:\WINDOWS\MsPrint32D.exe>  []
    <WinSysM><C:\WINDOWS\IGM.exe>  []
    <DbgHlp32><C:\WINDOWS\oxwwii.exe>  []
    <runeip><"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup>  [Beijing Rising Technology Co., Ltd.]
    <Storm2Set><; C:\WINDOWS\System32\rundll32.exe "C:\PROGRA~1\StormII\StormSet.dll",CheckEnv>  [(Verified)Beijing Baofeng Inc.]
    <mppds><C:\WINDOWS\mppds.exe>  []
    <Kvsc3><C:\WINDOWS\Kvsc3.exe>  []
    <cmdbcs><C:\WINDOWS\cmdbcs.exe>  []
    <upxdnd><C:\WINDOWS\upxdnd.exe>  []
    <msccrt><C:\WINDOWS\msccrt.exe>  []
    <MsIMMs32><C:\WINDOWS\MsIMMs32.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <MSDEG32><LYLoader.exe>  []
    <MSDWG32><LYLoadbr.exe>  [N/A]
    <MSDCG32    ><LYLeador.exe>  [N/A]
    <MSDOG32><LYLoador.exe>  [N/A]
    <MSDSG32><LYLoadar.exe>  [N/A]
    <MSDMG32><LYLoadmr.exe>  []
    <MSDHG32><LYLoadhr.exe>  [N/A]
    <MSDQG32><LYLoadqr.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><C:\WINDOWS\System32\zinforms.dll>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91974}><winforms.dll>  []
    <{AEB6717E-7E19-11d0-97EE-00C04FD91975}><zinforms.dll>  []
    <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\System32\shlhook.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
    <N/A><"C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
gototop
 

==================================
启动文件夹
N/A

==================================
服务
[9DF98F8E / 9DF98F8E][Stopped/Auto Start]
  <C:\WINDOWS\System32\E14E14D.EXE -k><Microsoft Corporation>
[ANIWZCSd Service / ANIWZCSdService][Stopped/Auto Start]
  <C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe><Alpha Networks Inc.>
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[SmartLinkService / SLService][Running/Auto Start]
  <slserv.exe><>

==================================
驱动程序
[AliIde / AliIde][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[ANIO Service / ANIO][Running/Auto Start]
  <\??\C:\WINDOWS\System32\ANIO.SYS><Alpha Networks Inc.>
[CmdIde / CmdIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  <system32\drivers\cmuda.sys><C-Media Inc>
[Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start]
  <System32\DRIVERS\e100b325.sys><Intel Corporation>
[VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  <System32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
[GMSIPCI / GMSIPCI][Stopped/Manual Start]
  <\??\G:\INSTALL\GMSIPCI.SYS><N/A>
[ialm / ialm][Running/Manual Start]
  <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[MegaIDE / MegaIDE][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[Mtlmnt5 / Mtlmnt5][Running/Manual Start]
  <System32\DRIVERS\SLDRV\Mtlmnt5.sys><>
[Mtlstrm / Mtlstrm][Stopped/Manual Start]
  <System32\DRIVERS\SLDRV\Mtlstrm.sys><>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\QQ2004\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RecAgent / RecAgent][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\SLDRV\RecAgent.sys><>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
[D-Link USB Wireless LAN Card Driver / RT73][Running/Manual Start]
  <System32\DRIVERS\Dr71WU.sys><Ralink Technology, Corp.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[SmartLink AMR_PCI Driver / Slntamr][Running/Manual Start]
  <System32\DRIVERS\SLDRV\slntamr.sys><>
[SlNtHal / SlNtHal][Stopped/Manual Start]
  <System32\DRIVERS\SLDRV\Slnthal.sys><>
[SlWdmSup / SlWdmSup][Running/Manual Start]
  <System32\DRIVERS\SLDRV\SlWdmSup.sys><>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <System32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera (ZS0211) / ZSMC211][Stopped/Manual Start]
  <System32\Drivers\ZS211.sys><ZSMC Corporation>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
  <system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
  <system32\drivers\ialmkchw.sys><Intel Corporation>
gototop
 

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\QQ2004\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[&Research]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\QQ2004\QQ.EXE, TENCENT>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\QQ2004\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[金山快译(&K)]
  {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\QQ2004\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\QQ2004\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\QQ2004\SendMMS.htm, N/A>

==================================
gototop
 

正在运行的进程
[PID: 560 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 780 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 804 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 852 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\LYMANGR.DLL]  [N/A, ]
[PID: 864 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1032 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1056 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1120 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1144 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
[PID: 1280 / SYSTEM][C:\WINDOWS\system32\slserv.exe]  [ , 4.00.07]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1304 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
[PID: 1396 / LOCAL SERVICE][C:\WINDOWS\System32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1776 / EADING][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 352 / EADING][C:\WINDOWS\System32\hkcmd.exe]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxhk.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3.0.0.2172]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 368 / EADING][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 376 / EADING][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynCOM.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynTPAPI.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 392 / EADING][C:\Program Files\D-Link\AirPlus G\AirGCFG.exe]  [D-Link, 3, 3, 1, 51123]
    [C:\WINDOWS\System32\wlanapi.dll]  [Alpha Networks Inc., 1, 3, 36, 51122]
    [C:\WINDOWS\System32\ANIOApi.dll]  [Alpha Networks Inc., 2, 0, 3, 51006]
    [C:\WINDOWS\System32\AQCKGen.dll]  [Alpha Networks Inc., 1, 0, 0, 30603]
    [C:\WINDOWS\System32\WlanApp.dll]  [Alpha Networks Inc., 1, 0, 15, 51118]
    [C:\Program Files\D-Link\AirPlus G\WlanMon.dll]  [D-Link, 3, 3, 1, 50907]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1300 / EADING][C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe]  [Alpha Networks Inc., 1, 0, 6, 41216]
    [C:\WINDOWS\System32\ANIWZCS2.DLL]  [Alpha Networks Inc., 2, 4, 38, 51122]
    [C:\WINDOWS\System32\AQCKGen.dll]  [Alpha Networks Inc., 1, 0, 0, 30603]
    [C:\WINDOWS\System32\ANIOApi.dll]  [Alpha Networks Inc., 2, 0, 3, 51006]
    [C:\WINDOWS\System32\WlanApp.dll]  [Alpha Networks Inc., 1, 0, 15, 51118]
    [C:\WINDOWS\System32\wlanapi.dll]  [Alpha Networks Inc., 1, 3, 36, 51122]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 404 / EADING][C:\WINDOWS\ZSSnp211.exe]  [ZSMCSNAP, 3, 6, 818, 7]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\System32\GenProtect.dll]  [N/A, ]
    [C:\WINDOWS\System32\Kvsc3.dll]  [N/A, ]
    [C:\WINDOWS\System32\AVPSrv.dll]  [N/A, ]
    [C:\WINDOWS\System32\mppds.dll]  [N/A, ]
    [C:\WINDOWS\System32\MsIMMs32.dll]  [N/A, ]
    [C:\WINDOWS\System32\NVDispDrv.dll]  [N/A, ]
    [C:\WINDOWS\System32\MsPrint32D.dll]  [N/A, ]
    [C:\WINDOWS\System32\cmdbcs.dll]  [N/A, ]
    [C:\WINDOWS\System32\upxdnd.dll]  [N/A, ]
    [C:\WINDOWS\System32\msccrt.dll]  [N/A, ]
    [C:\WINDOWS\System32\DbgHlp32.dll]  [N/A, ]
gototop
 

[PID: 452 / EADING][C:\WINDOWS\Domino.exe]  [, 3, 6, 818, 7]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
[PID: 548 / EADING][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.18]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 660 / EADING][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 920 / EADING][C:\WINDOWS\System32\k11919153275.exe]  [N/A, ]
[PID: 584 / EADING][C:\Program Files\MSN Messenger\msnmsgr.exe]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\MSNCore.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\msidcrl40.dll]  [Microsoft Corporation, 4.100.313.1]
    [C:\Program Files\MSN Messenger\ContactsUX.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\MSN Messenger\msgslang.8.1.0178.00.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\msgsres.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\MSGSWCAM.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\sirenacm.dll]  [Microsoft Corp., 8.1.0178.00]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\Program Files\MSN Messenger\lmcdata.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\contact.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\MSN Messenger\abssm.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\Program Files\MSN Messenger\custsat.dll]  [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[PID: 2216 / EADING][C:\WINDOWS\System32\k11919284575.exe]  [N/A, ]
[PID: 3956 / EADING][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.0.2004121400]
    [C:\WINDOWS\System32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
gototop
 

[C:\Program Files\QQ2004\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  [Amaze Soft, 1, 1, 4, 0]
    [c:\program files\google\googletoolbar2.dll]  [Google Inc., 4, 0, 1601, 4978]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2656 / EADING][C:\Program Files\Rising\AntiSpyware\Ras.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.62]
    [C:\Program Files\Rising\AntiSpyware\TopSoft.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.3]
    [C:\Program Files\Rising\AntiSpyware\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Rising\AntiSpyware\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\RasGui.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 0, 14]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\Program Files\Rising\AntiSpyware\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 24]
    [C:\Program Files\Rising\AntiSpyware\zip.dll]  [rising, 13, 0, 0, 1]
[PID: 296 / EADING][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll]  [Microsoft Corporation, 8.1.0178.00]
    [C:\WINDOWS\System32\Audiodev.dll]  [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1684 / EADING][C:\DOCUME~1\EADING\LOCALS~1\Temp\Rar$EX00.375\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\DOCUME~1\EADING\LOCALS~1\Temp\Rar$EX00.375\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
[PID: 3604 / EADING][C:\WINDOWS\System32\k11919320912.exe]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\zcyzzd.dll]  [N/A, ]
[PID: 3380 / EADING][C:\WINDOWS\System32\k11919320923.exe]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2860 / EADING][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SynTPFcs.dll]  [Synaptics, Inc., 7.4.4 27Mar03]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\System32\DB5EA3AB.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\System32\qqqyhr.dll]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\pxcaaf.dll]  [N/A, ]
    [C:\WINDOWS\System32\whzold.dll]  [N/A, ]
    [C:\WINDOWS\System32\knummz.dll]  [N/A, ]
    [C:\WINDOWS\System32\icclbh.dll]  [N/A, ]
    [C:\WINDOWS\System32\nqvrgy.dll]  [N/A, ]
    [C:\WINDOWS\System32\hqssyn.dll]  [N/A, ]
    [C:\WINDOWS\System32\hhowhr.dll]  [N/A, ]
    [C:\WINDOWS\System32\wtwnqh.dll]  [N/A, ]
    [C:\WINDOWS\System32\muvawc.dll]  [N/A, ]
    [C:\WINDOWS\System32\oxwwii.dll]  [N/A, ]
[PID: 2852 / EADING][C:\WINDOWS\IGM.exe]  [N/A, ]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[D:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[E:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1 http://www.3721.net/
127.0.0.1 3721.com
127.0.0.1 3721.net
127.0.0.1 cnsmin.3721.com
127.0.0.1 cnsmin.3721.net
127.0.0.1 download.3721.com
127.0.0.1 download.3721.net
127.0.0.1 www.3721.com
127.0.0.1 www.3721.net
127.0.0.1 bar.baidu.com
127.0.0.1 www.unionsky.cn

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 392, C:\PROGRAM FILES\D-LINK\AIRPLUS G\AIRGCFG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1300, C:\PROGRAM FILES\ANI\ANIWZCS2 SERVICE\WZCSLDR2.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 404, C:\WINDOWS\ZSSNP211.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 452, C:\WINDOWS\DOMINO.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 548, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 920, C:\WINDOWS\SYSTEM32\K11919153275.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2216, C:\WINDOWS\SYSTEM32\K11919284575.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2656, C:\PROGRAM FILES\RISING\ANTISPYWARE\RAS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2656, C:\PROGRAM FILES\RISING\ANTISPYWARE\RAS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 296, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3604, C:\WINDOWS\SYSTEM32\K11919320912.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3380, C:\WINDOWS\SYSTEM32\K11919320923.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2852, C:\WINDOWS\IGM.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

全部完整上传了,高手们求求帮忙啊,感激不尽!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT