瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 怎么办啊!重装系统都没用啊 这木马太恶心了!!

1   1  /  1  页   跳转

[求助] 怎么办啊!重装系统都没用啊 这木马太恶心了!!

怎么办啊!重装系统都没用啊 这木马太恶心了!!

这是那个日志
[CODE]

2009-01-29,17:50:52

System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描
    计划任务
    API HOOK
    隐藏进程


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><; C:\WINDOWS\system32\ctfmon.exe>  [(Infected) Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <amd_dc_opt><; C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe>  [File is missing]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><kpiohgkl.dll,klaginpl.dll,mpmiipbk.dll,jbfadhjj.dll,cfmfnglf.dll,fcgkblai.dll,nabdnafi.dll,aahpjnnm.dll,,flobkcei.dll,pjhlifcj.dll,fiekoaom.dll,flflbjlj.dll,anmhnjnd.dll>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{F5F5B353-8A98-44B4-9CB9-0E51F2387358}><C:\WINDOWS\system32\flflbjlj.dll>  []
    <{7ABD7AF2-C737-4FD5-9AB1-E5A4AF4261CE}><C:\WINDOWS\system32\nabdnafi.dll>  []
    <{93152FC3-5705-45EA-B9BC-00E0C1926A4C}><C:\WINDOWS\system32\pjhlifcj.dll>  []
    <{FC04B5A2-053E-49A3-A33C-101365579298}><C:\WINDOWS\system32\fcgkblai.dll>  []
    <{F2E48A86-ABB8-43CB-8CB8-BB729B1782C1}><C:\WINDOWS\system32\fiekoaom.dll>  []
    <{CF6F705F-C856-4FB8-B07F-13335EC1BB6C}><C:\WINDOWS\system32\cfmfnglf.dll>  []
    <{3BFAD133-DE4A-4160-B475-38643C5E4DEE}><C:\WINDOWS\system32\jbfadhjj.dll>  []
    <{696229B4-758E-4830-BDF7-98BAE81948F3}><C:\WINDOWS\system32\mpmiipbk.dll>  []
    <{45A02795-EBD0-416D-96E1-10FEADF8E97E}><C:\WINDOWS\system32\klaginpl.dll>  []
    <{49281045-AED2-4C7D-89CA-4BE3E2AD68DA}><C:\WINDOWS\system32\kpiohgkl.dll>  []
    <{A761737D-2F13-4504-9133-F08F7F22D0A4}><C:\WINDOWS\system32\anmhnjnd.dll>  []
    <{AA193776-4AD2-4CBC-A61C-1C43F06849EC}><C:\WINDOWS\system32\aahpjnnm.dll>  []
    <{F58B4CE2-E0C3-4237-B423-AAF5E54321DE}><C:\WINDOWS\system32\flobkcei.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <F5F5B353><C:\WINDOWS\system32\flflbjlj.dll>  []
    <93152FC3><C:\WINDOWS\system32\pjhlifcj.dll>  []
    <F2E48A86><C:\WINDOWS\system32\fiekoaom.dll>  []
    <CF6F705F><C:\WINDOWS\system32\cfmfnglf.dll>  []
    <7ABD7AF2><C:\WINDOWS\system32\nabdnafi.dll>  []
    <45A02795><C:\WINDOWS\system32\klaginpl.dll>  []
    <696229B4><C:\WINDOWS\system32\mpmiipbk.dll>  []
    <3BFAD133><C:\WINDOWS\system32\jbfadhjj.dll>  []
    <F58B4CE2><C:\WINDOWS\system32\flobkcei.dll>  []
    <AA193776><C:\WINDOWS\system32\aahpjnnm.dll>  []
    <49281045><C:\WINDOWS\system32\kpiohgkl.dll>  []
    <FC04B5A2><C:\WINDOWS\system32\fcgkblai.dll>  []
    <A761737D><C:\WINDOWS\system32\anmhnjnd.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
    <WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Component Publisher]

==================================
启动文件夹
N/A

==================================
服务
[Contrl Center of Storm Media / ccosm][Stopped/Disabled]
  <C:\Program Files\StormII\stormliv.exe /asservice><(File is missing)>
[HID Input Service / HidServ][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

==================================
驱动程序
[360procmon / 360procmon][Running/Manual Start]
  <\??\D:\Program Files\360\360Safe\safemon\360procmon.sys><>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[AmdK8 Compatible Device / AmdK8][Stopped/Manual Start]
  <System32\drivers\amdk8.sys><Advanced Micro Devices>
[AMD Low Level Device Driver / AmdLLD][Running/Manual Start]
  <system32\DRIVERS\AmdLLD.sys><AMD, Inc.>
[Dritek Keyboard Filter Driver / DKbFltr][Running/Manual Start]
  <system32\DRIVERS\DKbFltr.sys><Dritek System Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[msiffei / msiffei][Stopped/Manual Start]
  <System32\Drivers\msiffei.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtenicxp.sys><Realtek Semiconductor Corporation>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
  <\??\C:\WINDOWS\system32\Drivers\safeboxkrnl.sys><360安全中心>
[Safe Mon 360 / SafeMon0][Running/System Start]
  <\??\C:\WINDOWS\system32\CDC7F049.dat><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[242531 / 242531][Stopped/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>

==================================
浏览器加载项
[ThunderAtOnce Class]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Create Mobile Favorite]
  {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} <d:\PROGRA~1\MICROS~1\INetRepl.dll, (Signed) Microsoft Corporation>
[Create Mobile Favorite]
  {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} <d:\PROGRA~1\MICROS~1\INetRepl.dll, (Signed) Microsoft Corporation>
[]
  {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
[ThunderAtOnce Class]
  {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
  {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} <, >
[]
  {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} <, >
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[]
  {6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF} <C:\Program Files\Internet Explorer\PowerNeNt.Onz, N/A>
[360SafeLive]
  {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\Program Files\360\360Safe\live.dll, (Signed) 360.cn>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
[]
  {E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[使用迅雷下载]
  <C:\Program Files\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>

==================================
正在运行的进程
[PID: 664 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 720 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 744 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 788 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 800 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 948 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 1028 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 1068 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\System32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\System32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\System32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\System32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\System32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\System32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\System32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\System32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\System32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\System32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\System32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\System32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\System32\kpiohgkl.dll]  [N/A, ]
[PID: 1180 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 1220 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
   

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MAXTHON 2.0)
分享到:
gototop
 

回复:怎么办啊!重装系统都没用啊 这木马太恶心了!!

[C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 1384 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 1580 / Administrator][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
    [C:\WINDOWS\system32\browselc.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
    [C:\WINDOWS\system32\shdoclc.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1004]
[PID: 1628 / Administrator][C:\WINDOWS\system32\conime.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]  [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 1740 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.11.7792]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1780 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
[PID: 188 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\System32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\System32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\System32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\System32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\System32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\System32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\System32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\System32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\System32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\System32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\System32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\System32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\System32\kpiohgkl.dll]  [N/A, ]
[PID: 1616 / Administrator][D:\Program Files\Maxthon2\Maxthon.exe]  [Maxthon International ltd., 2, 1, 5, 1250]
    [D:\Program Files\Maxthon2\mxpp.dll]  [Maxthon International ltd., 1, 0, 0, 241]
    [D:\Program Files\Maxthon2\MxSk.dll]  [Maxthon, 1, 0, 0, 413]
    [D:\Program Files\Maxthon2\MxProxy2.dll]  [Maxthon International ltd., 1, 0, 0, 4106]
    [D:\Program Files\Maxthon2\MxExt.dll]  [N/A, ]
    [D:\Program Files\Maxthon2\MxUI.dll]  [Maxthon International, 3, 3, 0, 9]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\Maxthon2\mxtool.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Maxthon2\maxzlib.dll]  [, 1.2.3]
    [D:\Program Files\Maxthon2\Modules\MxWebBoost\MxWebBoost.dll]  [Maxthon, 1,0,2,1267]
    [D:\Program Files\Maxthon2\mxdb.dll]  [Max, 3, 5, 3, 125]
    [D:\Program Files\Maxthon2\Modules\MxHistory\MxHistory.dll]  [Maxthon International ltd., 1, 0, 0, 302]
    [C:\WINDOWS\system32\shdoclc.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
    [C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 4.0.0.1959]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1004]
[PID: 440 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.797\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
[PID: 1476 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.797\SRE5adef2a7.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\cfmfnglf.dll]  [N/A, ]
    [C:\WINDOWS\system32\flobkcei.dll]  [N/A, ]
    [C:\WINDOWS\system32\pjhlifcj.dll]  [N/A, ]
    [C:\WINDOWS\system32\fiekoaom.dll]  [N/A, ]
    [C:\WINDOWS\system32\flflbjlj.dll]  [N/A, ]
    [C:\WINDOWS\system32\anmhnjnd.dll]  [N/A, ]
    [C:\WINDOWS\system32\fcgkblai.dll]  [N/A, ]
    [C:\WINDOWS\system32\nabdnafi.dll]  [N/A, ]
    [C:\WINDOWS\system32\aahpjnnm.dll]  [N/A, ]
    [C:\WINDOWS\system32\kpiohgkl.dll]  [N/A, ]
    [C:\WINDOWS\system32\klaginpl.dll]  [N/A, ]
    [C:\WINDOWS\system32\mpmiipbk.dll]  [N/A, ]
    [C:\WINDOWS\system32\jbfadhjj.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1004]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.797\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      v.onondown.com.cn
127.0.0.2      ymsdasdw1.cn
127.0.0.3      h96b.info
127.0.0.0      xxx.zttwp.cn
127.0.0.0      www.hackerbf.cn
127.0.0.0      ww.popdm.cn
127.1.1.1      bbt.etimes888.com
127.1.1.1      219.147.13.53
127.1.1.1      dl.360safe.com
127.1.1.1      20068080.cn
127.1.1.1      l.neter888.cn
127.1.1.1      stat.untang.com
127.1.1.1      www.ikdy.cn
127.0.0.0      geekbyfeng.cn
127.0.0.0      121.14.101.68
127.0.0.0      ppp.etimes888.com
127.0.0.0      www.bypk.com
127.0.0.0      CSC3-2004-crl.verisign.com
127.0.0.1      va9sdhun23.cn
127.0.0.0      udp.hjob123.com
127.1.1.1      999.hfdy2828.com
127.1.1.1      www.hfdy2929.com
127.1.1.1      www.xiazaide1.cn
127.1.1.1      www.vuf51579.cn
127.1.1.1      wm.eo2q.cn
127.1.1.1      d.www-263.com
127.1.1.1      www.ssy1688.cn
127.1.1.1      121.12.173.218
127.1.1.1      qq.18i16.net
127.1.1.1      a.baidu-6661.com
127.1.1.1      www.vuf51579.cn
127.1.1.1      www.1079223105.cn
127.1.1.1      home.xzx6.cn
127.1.1.1      top.fgc3.cn
127.1.1.1      165.246.44.228
127.1.1.1      wwww.ttfafa.com
127.1.1.1      pa.tt-09.com
127.0.0.2      bnasnd83nd.cn
127.0.0.0      www.gamehacker.com.cn
127.0.0.0      gamehacker.com.cn
127.1.1.1      www.cctv-100008.cn
127.1.1.1      222.73.208.141
127.0.0.3      adlaji.cn
127.1.1.1      aiyyw.com
127.0.0.1      858656.com
127.1.1.1      bnasnd83nd.cn
127.0.0.1      my123.com
127.0.0.0      user1.12-27.net
127.0.0.1      8749.com
127.0.0.0      fengent.cn
127.0.0.1      4199.com
127.0.0.1      user1.16-22.net
127.0.0.1      7379.com
127.0.0.1      2be37c5f.3f6e2cc5f0b.com
127.0.0.1      7255.com
127.0.0.1      user1.23-12.net
127.0.0.1      3448.com
127.0.0.1      www.guccia.net
127.0.0.1      7939.com
127.0.0.1      a.o1o1o1.nEt
127.0.0.1      8009.com
127.0.0.1      user1.12-73.cn
127.0.0.1      piaoxue.com
127.0.0.1      3n8nlasd.cn
127.0.0.1      kzdh.com
127.0.0.0      www.sony888.cn
127.0.0.1      about.blank.la
127.0.0.0      user1.asp-33.cn
127.0.0.1      6781.com
127.0.0.0      www.netkwek.cn
127.0.0.1      7322.com
127.0.0.0      ymsdkad6.cn
127.0.0.1      localhost
127.0.0.0      www.lkwueir.cn
127.0.0.1      06.jacai.com
127.0.1.1      user1.23-17.net
127.0.0.1      1.jopenkk.com
127.0.0.0      upa.luzhiai.net
127.0.0.1      1.jopenqc.com
127.0.0.0      www.guccia.net
127.0.0.1      1.joppnqq.com
127.0.0.0      4m9mnlmi.cn
127.0.0.1      1.xqhgm.com
127.0.0.0      mm119mkssd.cn
127.0.0.1      100.332233.com
127.0.0.0      61.128.171.115:8080
127.0.0.1      121.11.90.79
127.0.0.0      www.1119111.com
127.0.0.1      121565.net
127.0.0.0      win.nihao69.cn
127.0.0.1      125.90.88.38
127.0.0.1      16888.6to23.com
127.0.0.1      2.joppnqq.com
127.0.0.0      puc.lianxiac.net
127.0.0.1      204.177.92.68
127.0.0.0      pud.lianxiac.net
127.0.0.1      210.74.145.236
127.0.0.0      210.76.0.133
127.0.0.1      219.129.239.220
127.0.0.0      61.166.32.2
127.0.0.1      219.153.40.221
127.0.0.0      218.92.186.27
127.0.0.1      219.153.46.27
127.0.0.0      www.fsfsfag.cn
127.0.0.1      219.153.52.123
127.0.0.0      ovo.ovovov.cn
127.0.0.1      221.195.42.71
127.0.0.0      dw.com.com
127.0.0.1      222.73.218.115
127.0.0.1      203.110.168.233:80
127.0.0.1      3.joppnqq.com
127.0.0.1      203.110.168.221:80
127.0.0.1      363xx.com
127.0.0.1      www1.ip10086.com.cm
127.0.0.1      4199.com
127.0.0.1      blog.ip10086.com.cn
127.0.0.1      43242.com
127.0.0.1      www.ccji68.cn
127.0.0.1      5.xqhgm.com
127.0.0.0      t.myblank.cn
127.0.0.1      520.mm5208.com
127.0.0.0      x.myblank.cn
127.0.0.1      59.34.131.54
127.0.0.1      210.51.45.5
127.0.0.1      59.34.198.228
127.0.0.1      www.ew1q.cn
127.0.0.1      59.34.198.88
127.0.0.1      59.34.198.97
127.0.0.1      60.190.114.101
127.0.0.1      60.190.218.34
127.0.0.0      qq-xing.com.cn
127.0.0.1      60.191.124.252
127.0.0.1      61.145.117.212
127.0.0.1      61.157.109.222
127.0.0.1      75.126.3.216
127.0.0.1      220.250.64.21
127.0.0.1      75.126.3.217
127.0.0.1      75.126.3.218
127.0.0.0      59.125.231.177:17777
127.0.0.1      75.126.3.220
127.0.0.1      75.126.3.221
127.0.0.1      75.126.3.222
127.0.0.1      772630.com
127.0.0.1      832823.cn
127.0.0.1      8749.com
127.0.0.1      888.jopenqc.com
127.0.0.1      89382.cn
127.0.0.1      8v8.biz
127.0.0.1      97725.com
127.0.0.1      9gg.biz
127.0.0.1      www.9000music.com
127.0.0.1      test.591jx.com
127.0.0.1      a.topxxxx.cn
127.0.0.1      picon.chinaren.com
127.0.0.1      www.5566.net
127.0.0.1      p.qqkx.com
127.0.0.1      news.netandtv.com
127.0.0.1      z.neter888.cn
127.0.0.1      b.myblank.cn
127.0.0.1      wvw.wokutu.com
127.0.0.1      unionch.qyule.com
127.0.0.1      www.qyule.com
127.0.0.1      it.itjc.cn
127.0.0.1      www.linkwww.com
127.0.0.1      vod.kaicn.com
127.0.0.1      www.tx8688.com
127.0.0.1      b.neter888.cn
127.0.0.1      promote.huanqiu.com
127.0.0.1      www.huanqiu.com
127.0.0.1      www.haokanla.com
127.0.0.1      play.unionsky.cn
127.0.0.1      www.52v.com
127.0.0.1      www.gghka.cn
127.0.0.1      icon.ajiang.net
127.0.0.1      new.ete.cn
127.0.0.1      www.stiae.cn
127.0.0.1      o.neter888.cn
127.0.0.1      comm.jinti.com
127.0.0.1      www.google-analytics.com
127.0.0.1      hz.mmstat.com
127.0.0.1      www.game175.cn
127.0.0.1      x.neter888.cn
127.0.0.1      z.neter888.cn
127.0.0.1      p.etimes888.com
127.0.0.1      hx.etimes888.com
127.0.0.1      abc.qqkx.com
127.0.0.1      dm.popdm.cn
127.0.0.1      www.yl9999.com
127.0.0.1      www.dajiadoushe.cn
127.0.0.1      v.onondown.com.cn
127.0.0.1      www.interoo.net
127.0.0.1      bally1.bally-bally.net
127.0.0.1      www.bao5605509.cn
127.0.0.1      www.rty456.cn
127.0.0.1      www.werqwer.cn
127.0.0.1      1.360-1.cn
127.0.0.1      user1.23-16.net
127.0.0.1      www.guccia.net
127.0.0.1      www.interoo.net
127.0.0.1      upa.netsool.net
127.0.0.1      js.users.51.la
127.0.0.1      vip2.51.la
127.0.0.1      web.51.la
127.0.0.1      qq.gong2008.com
127.0.0.1      2008tl.copyip.com
127.0.0.1      tla.laozihuolaile.cn
127.0.0.1      www.tx6868.cn
127.0.0.1      p001.tiloaiai.com
127.0.0.1      s1.tl8tl.com
127.0.0.1      s1.gong2008.com
127.0.0.1      4b3ce56f9g.3f6e2cc5f0b.com
127.0.0.1      2be37c5f.3f6e2cc5f0b.com

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 744, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1740, C:\WINDOWS\SYSTEM32\NVSVC32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 440, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.797\SRENGLDR.EXE]

==================================
计划任务
[已启用] SogouImeMgr.job
        C:\PROGRA~1\SOGOUI~1\400~1.195\PinyinRepair.exe

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]

版主给看看啊  急!!!!!!
gototop
 

回复:怎么办啊!重装系统都没用啊 这木马太恶心了!!

我用那个你说的软件 一粘贴那木马日志点开始处理 就重启了 但是还是会有啊!
gototop
 

回复:怎么办啊!重装系统都没用啊 这木马太恶心了!!

而且360不停的说有新增的系统可执行挂钩
很多木马是在TEMP下的 粉碎文件后 一上网又有了
gototop
 

回复:怎么办啊!重装系统都没用啊 这木马太恶心了!!

哦 但这个日志里看出了问题么 因为又好像没事了
360查杀没有木马 但是那个提升新增系统挂钩还是会有
gototop
 

回复:怎么办啊!重装系统都没用啊 这木马太恶心了!!

好 等下ha
gototop
 

回复: 怎么办啊!重装系统都没用啊 这木马太恶心了!!

这个

附件附件:

文件名:SREngLOG.log
下载次数:106
文件类型:application/octet-stream
文件大小:
上传时间:2009-1-29 18:19:16
描述:log

gototop
 

回复:怎么办啊!重装系统都没用啊 这木马太恶心了!!

天哥你介绍下 一般电脑装哪几个防毒清理安全软件较好!
瑞星是有的
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT