设为首页收藏本站

八达网

 找回密码
 注册
12
返回列表 发新帖
楼主: TheRytheM
打印 上一主题 下一主题

电脑高手进...救救我家里的电脑吧.........

[复制链接]

866

主题

22

好友

10万

积分

黑暗执政官

闻昆吾方始,知秋珉而入林

2007年度八达十大杰出青年 2008年度八达十大水友

31
发表于 2007-7-19 17:42 |只看该作者

回复 #30 TheRytheM 的帖子

啊哦。。。。我看错了。。。是这个

[ 本帖最后由 hysteria 于 2007-7-19 17:45 编辑 ]
卿晓寒夜,须知朝阳
胸大了不起么,爽的又不是自己!
回复

使用道具 举报

866

主题

22

好友

10万

积分

黑暗执政官

闻昆吾方始,知秋珉而入林

2007年度八达十大杰出青年 2008年度八达十大水友

32
发表于 2007-7-19 17:46 |只看该作者
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <bgswitch><C:\WINDOWS\system32\bgswitch.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <AVP><"D:\卡巴\avp.exe">  [Kaspersky Lab]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
    <360Safetray><D:\360safe\safemon\360Tray.exe /start>  [奇虎网]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <visin><C:\WINDOWS\system32\visin.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]

==================================
启动文件夹
N/A

==================================
服务
[卡巴斯基反病毒6.0个人版 / AVP][Running/Auto Start]
  <D:\卡巴\avp.exe -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>

==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[kl1 / kl1][Running/Boot Start]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>

==================================
浏览器加载项
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\360safe\safemon\safemon.dll, >
[Web反病毒统计]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\卡巴\scieplugin.dll, Kaspersky Lab>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[360SafeLive]
  {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\360safe\live.dll, 360safe.com>
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\360safe\safemon\safemon.dll, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 636 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 760 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 784 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 828 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 840 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1000 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1064 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1160 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1212 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1276 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1672 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\卡巴\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1712 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1980 / Administrator][D:\卡巴\avp.exe]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\FSSync.dll]  [Kaspersky Lab, 6.0.5.621]
    [D:\卡巴\AVPGS.PPL]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\params.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\winreg.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\avpgui.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\nfio.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\basegui.ppl]  [Kaspersky Lab, 6.0.2.621]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [d:\卡巴\thpimpl.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\qb.ppl]  [Kaspersky Lab, 6.0.2.621]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 2012 / Administrator][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.27]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 144 / Administrator][D:\360safe\safemon\360Tray.exe]  [奇虎网, 3, 5, 2, 1001]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 5, 0, 1001]
    [D:\360safe\AntiAdwa.dll]  [360Safe.com, 3, 5, 1, 1001]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 200 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 348 / SYSTEM][D:\卡巴\avp.exe]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\FSSync.dll]  [Kaspersky Lab, 6.0.5.621]
    [D:\卡巴\AVPGS.PPL]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\params.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\winreg.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\tm.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\nfio.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\bl.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\wmihlpr.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\ndetect.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\crpthlpr.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\schedule.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\timer.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\thpimpl.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\lic60.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\l_llio.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\sfdb.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\ichk2.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\icheckersa.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\smtpprotocoller.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\httpanlz.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\hashcont.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\trafficmonitor2.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\CKAHUM.dll]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\CKAHComm.dll]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\ckahrule.dll]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\pop3protocoller.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\hccmp.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\imapprotocoller.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\iwgen.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\nntpprotocoller.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\tempfile.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\uniarc.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\minizip.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\cab.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\arj.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\rar.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\lha.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\mdb.ppl]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\MAPI32.dll]  [Microsoft Corporation, 1.0.2536.0 (XPClient.010817-1148)]
    [d:\卡巴\msoe.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\qb.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\prseqio.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\dmap.ppl]  [Kaspersky Lab, 6.0.2.621]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
    [d:\卡巴\inflate.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\mdmap.ppl]  [Kaspersky Lab, 6.0.2.621]
[PID: 448 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 136 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 2240 / Administrator][C:\Program Files\Windows Media Player\wmplayer.exe]  [Microsoft Corporation, 10.00.00.3802]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\卡巴\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\params.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\tempfile.ppl]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 2736 / Administrator][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 3692 / Administrator][D:\Program Files\Tencent\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\Program Files\Tencent\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\BasicCtrlDll.dll]  [Tencent, 6, 0, 200, 320]
    [D:\Program Files\Tencent\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\Program Files\Tencent\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\Program Files\Tencent\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\Program Files\Tencent\QQAPI.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\Program Files\Tencent\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [D:\Program Files\Tencent\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [D:\Program Files\Tencent\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQMainFrame.dll]  [N/A, ]
    [D:\Program Files\Tencent\CQQApplication.dll]  [N/A, ]
    [D:\Program Files\Tencent\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQKnowledgeSearch.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQAllInOne.dll]  [N/A, ]
    [D:\Program Files\Tencent\GroupLive.dll]  [N/A, ]
    [D:\Program Files\Tencent\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [D:\Program Files\Tencent\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\Tencent\QQSpace.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [D:\Program Files\Tencent\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQSysMsgMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQPlugin.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\卡巴\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\Program Files\Tencent\QRingMng.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\Tencent\QQCustomFace.dll]  [N/A, ]
    [D:\Program Files\Tencent\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [D:\Program Files\Tencent\QQAvatar.dll]  [N/A, ]
    [D:\Program Files\Tencent\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\Program Files\Tencent\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\Program Files\Tencent\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\BQQApplication.dll]  [N/A, ]
    [D:\Program Files\Tencent\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\Program Files\Tencent\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 271]
    [D:\Program Files\Tencent\QQSceneMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
    [C:\WINDOWS\system32\msadp32.acm]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\卡巴\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\params.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\tempfile.ppl]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,22,0]
    [D:\Program Files\Tencent\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Tencent\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [D:\Program Files\Tencent\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [D:\Program Files\Tencent\QQFileTransfer.dll]  [Tencent, 0, 3, 3, 5]
    [D:\Program Files\Tencent\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 3752 / Administrator][D:\Program Files\Tencent\TIMPlatfrom.exe]  [tencent, 0, 3, 1, 8]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\Program Files\Tencent\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 1756 / Administrator][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
[PID: 2724 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\卡巴\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\卡巴\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\卡巴\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\卡巴\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\params.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\tempfile.ppl]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,22,0]
    [d:\卡巴\nfio.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\basegui.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\thpimpl.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\卡巴\FSSync.dll]  [Kaspersky Lab, 6.0.5.621]
    [d:\卡巴\winreg.ppl]  [Kaspersky Lab, 6.0.2.621]
[PID: 2872 / Administrator][D:\sreng\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]
    [D:\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
    [D:\sreng\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1       localhost

==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1980, D:\卡巴\AVP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1980, D:\卡巴\AVP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 144, D:\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 144, D:\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 348, D:\卡巴\AVP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3692, D:\PROGRAM FILES\TENCENT\QQ.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3752, D:\PROGRAM FILES\TENCENT\TIMPLATFROM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3752, D:\PROGRAM FILES\TENCENT\TIMPLATFROM.EXE]

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
入口点错误:FindWindowA (危险等级: 高,  被下面模块所HOOK: 0x00E83CCD)
入口点错误:FindWindowExA (危险等级: 高,  被下面模块所HOOK: 0x00E83E6D)
入口点错误:FindWindowExW (危险等级: 高,  被下面模块所HOOK: 0x00E83F3D)
入口点错误:FindWindowW (危险等级: 高,  被下面模块所HOOK: 0x00E83D9D)
入口点错误:SendMessageA (危险等级: 高,  被下面模块所HOOK: 0x00E8400D)
入口点错误:SendMessageW (危险等级: 高,  被下面模块所HOOK: 0x00E840DD)

==================================
隐藏进程
N/A

==================================


[/CODE]
卿晓寒夜,须知朝阳
胸大了不起么,爽的又不是自己!
回复

使用道具 举报

821

主题

0

好友

5万

积分

光明执政官

嗯哈哈

33
发表于 2007-7-19 17:47 |只看该作者
是不是这个?????? 大家帮忙看看 管理日志里的

日志.rar

8.36 KB, 下载次数: 3

回复

使用道具 举报

821

主题

0

好友

5万

积分

光明执政官

嗯哈哈

34
发表于 2007-7-19 17:49 |只看该作者
完全看不懂  -  -
回复

使用道具 举报

0

主题

0

好友

1万

积分

航母

35
发表于 2007-7-19 17:51 |只看该作者
都烧焦了
还是割了吧
回复

使用道具 举报

0

主题

0

好友

8万

积分

仲裁者

36
发表于 2007-7-19 17:54 |只看该作者

回复 #33 TheRytheM 的帖子

就这个启动项一个有问题,其他的好像都没什么。
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <visin><C:\WINDOWS\system32\visin.exe>  [Microsoft Corporation]
还有就是临时文件夹的这个比较可疑,所有进程里边都被插入这个了。
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [Beijing Rising Tech. Co., Ltd., 1, 2, 0, 5]

先清空临时文件夹,然后用SREng把注册表启动项里的除了卡巴的都删掉。
再用冰刃把那个病毒文件删除,最后再用卡巴全盘杀下毒试试。
冰刃下载地址:http://mail.ustc.edu.cn/~jfpan/download/IceSword120_cn.zip

PS:你这报告不全呀,服务项就两个?

[ 本帖最后由 PPLN 于 2007-7-19 17:59 编辑 ]
回复

使用道具 举报

1

主题

0

好友

1973

积分

坦克

战队
FoR..
种族
Protoss
37
发表于 2007-7-19 17:56 |只看该作者
LS几位的方法~基本没用!可悲!
回复

使用道具 举报

821

主题

0

好友

5万

积分

光明执政官

嗯哈哈

38
发表于 2007-7-19 18:00 |只看该作者
原帖由 PPLN 于 2007-7-19 17:54 发表
就这个启动项一个有问题,其他的好像都没什么。
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
      [Microsoft Corporation]
还有就是临时文件夹的这个比较可疑 ...


清空临时文件架是什么意思??? 是不是把除C盘所有的文件架都删了?? 还有 杀完了是不是再从装一边???????
回复

使用道具 举报

0

主题

0

好友

8万

积分

仲裁者

39
发表于 2007-7-19 18:02 |只看该作者

回复 #38 TheRytheM 的帖子

就是把C:\Documents and Settings\Administrator\Local Settings\Temp这个文件夹下的东西全部删除。有删不掉的就用冰刃强制删除。
回复

使用道具 举报

821

主题

0

好友

5万

积分

光明执政官

嗯哈哈

40
发表于 2007-7-19 18:14 |只看该作者
原帖由 PPLN 于 2007-7-19 17:54 发表
就这个启动项一个有问题,其他的好像都没什么。
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
      [Microsoft Corporation]
还有就是临时文件夹的这个比较可疑 ...



我又扫了一遍 全都在这里了 我电脑才从装过 所以电脑里装的东西不多

我把你说的那个文件架的东西都删了    现在准备用卡巴全盘杀一边

SREngLOG.rar

2.71 KB, 下载次数: 2

回复

使用道具 举报

0

主题

0

好友

8万

积分

仲裁者

41
发表于 2007-7-19 18:25 |只看该作者

回复 #40 TheRytheM 的帖子

我怎么老感觉你的报告不全,上次是服务,这次是注册表。
如果你没装过瑞星卡卡的话那这个应该就是病毒了。
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvA.tmp]  [N/A, ]
这个删不掉吗?每个进程都有这个。
回复

使用道具 举报

1

主题

0

好友

1973

积分

坦克

战队
FoR..
种族
Protoss
42
发表于 2007-7-19 19:25 |只看该作者
加QQ远程吧!这样最直观!
回复

使用道具 举报

7

主题

0

好友

2万

积分

大和

43
发表于 2007-7-19 19:33 |只看该作者
是不是天气太热了
自动关机啊
回复

使用道具 举报

intothegame4 该用户已被删除
44
发表于 2007-7-19 19:34 |只看该作者
提示: 作者被禁止或删除 内容自动屏蔽
回复

使用道具 举报

321

主题

2

好友

5万

积分

光明执政官

拉票小王子

45
发表于 2007-7-19 19:45 |只看该作者
唉................
回复

使用道具 举报

0

主题

0

好友

8万

积分

仲裁者

46
发表于 2007-7-19 19:49 |只看该作者
原帖由 天命在弦 于 2007-7-19 19:45 发表
唉................

你的也还没搞定么?
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

手机版|Archiver|八达网    

GMT+8, 2026-7-3 17:16

Powered by Discuz! X2.5

© 2001-2012 Comsenz Inc.

回顶部