查看: 1902|回复: 4
收起左侧

求助啊,各位大哥.帮忙看看该怎么办?

[复制链接]
蓝色牛仔裤
发表于 2007-7-21 20:58:02 | 显示全部楼层 |阅读模式
牛仔裤不在,他叫我上来找你们各位大哥帮忙,说你们肯定能帮到我的..
先谢谢拉!
中毒之后打不开硬盘,提示如下:

未命名.PNG


  1. 2007-07-21,20:29:36
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18.     <DrvMon.exe><C:\WINDOWS\system32\DrvMon.exe>  [Alcor Micro, Corp.]
  19.     <ArpSet><D:\江门有线\登陆软件\ArpSet\ArpSet.bat>  []
  20.     <QQDownload><"C:\Program Files\Tencent\QQDownload\QQDownload.exe" autostart>  [N/A]
  21. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  22.     <load><>  [N/A]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  24.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  25.     <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
  26.     <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
  27.     <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)Microsoft Windows Publisher]
  28.     <Easy-PrintToolBox><C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon>  [CANON INC.]
  29.     <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
  30.     <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  31.     <vbe><C:\WINDOWS\u.vbe>  []
  32.     <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
  33.     <stup.exe><Rundll32.exe C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll,Rundll32 R>  [TENCENT]
  34.     <360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start>  [奇虎网]
  35. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  36.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  37.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  38. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  39.     <AppInit_DLLs><>  [N/A]
  40. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  41.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  43.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  45.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  47.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  49.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  51.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  53.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  55.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  56. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  57.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
  58. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  59.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  60. ==================================
  61. 启动文件夹
  62. [腾讯QQ]
  63.   <C:\Documents and Settings\Admin\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>
  64. [QQ游戏启动加速程序]
  65.   <C:\Documents and Settings\Admin\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> C:\PROGRA~1\Tencent\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
  66. ==================================
  67. 服务
  68. [卡巴斯基反病毒软件6.0 / AVP][Running/Auto Start]
  69.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  70. [Human Interface Device Access / HidServ][Stopped/Disabled]
  71.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  72. ==================================
  73. 驱动程序
  74. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  75.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  76. [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  77.   <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
  78. [GMSIPCI / GMSIPCI][Stopped/Manual Start]
  79.   <\??\G:\INSTALL\GMSIPCI.SYS><N/A>
  80. [kl1 / kl1][Running/Boot Start]
  81.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  82. [KLIF / KLIF][Running/System Start]
  83.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  84. [New0 / New0][Running/Auto Start]
  85.   <\??\C:\WINDOWS\system32\new.sys><N/A>
  86. [nv / nv][Stopped/Manual Start]
  87.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  88. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  89.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  90. [S3Psddr / S3Psddr][Running/Manual Start]
  91.   <system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
  92. [S3SavageNB / S3SavageNB][Stopped/Manual Start]
  93.   <system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
  94. [Secdrv / Secdrv][Stopped/Manual Start]
  95.   <system32\DRIVERS\secdrv.sys><N/A>
  96. [VIA AGP Filter / viaagp1][Running/Boot Start]
  97.   <\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
  98. [ViaIde / ViaIde][Running/Boot Start]
  99.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  100. [VIA AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
  101.   <system32\drivers\viaudios.sys><VIA Technologies, Inc.>
  102. [Vsp / Vsp][Stopped/Manual Start]
  103.   <\??\C:\WINDOWS\system32\drivers\Vsp.sys><N/A>
  104. ==================================
  105. 浏览器加载项
  106. [QQCycloneHelper Class]
  107.   {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper02.dll, 腾讯公司>
  108. [Tencent Browser Helper]
  109.   {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\SSPlus\SAddr.dll, Tencent>
  110. [NavigatMon Class]
  111.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
  112. [Web反病毒保护]
  113.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  114. [CibaCtrl Class]
  115.   {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
  116. [信息检索(&R)]
  117.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  118. [JoyoCtrl Class]
  119.   {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
  120. [QQ]
  121.   {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
  122. [Messenger]
  123.   {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, N/A>
  124. [金山快译(&K)]
  125.   {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll, >
  126. [Easy-WebPrint]
  127.   {327C2873-E90D-4c37-AA9D-10AC9BABA46C} <C:\Program Files\Canon\Easy-WebPrint\Toolband.dll, >
  128. [Shockwave Flash Object]
  129.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx, Macromedia, Inc.>
  130. [Rising Web Scan Object]
  131.   {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
  132. [QQCycloneHelper Class]
  133.   {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper02.dll, 腾讯公司>
  134. [Tencent Browser Helper]
  135.   {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\SSPlus\SAddr.dll, Tencent>
  136. [Easy-WebPrint]
  137.   {327C2873-E90D-4C37-AA9D-10AC9BABA46C} <C:\Program Files\Canon\Easy-WebPrint\Toolband.dll, >
  138. [金山快译(&K)]
  139.   {6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <C:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll, >
  140. [360SafeLive]
  141.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
  142. [Microsoft Web 浏览器]
  143.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
  144. [CibaCtrl Class]
  145.   {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
  146. [NavigatMon Class]
  147.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
  148. [JoyoCtrl Class]
  149.   {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
  150. [Shockwave Flash Object]
  151.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx, Macromedia, Inc.>
  152. [Rising Web Scan Object]
  153.   {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
  154. [&使用超级旋风下载]
  155.   <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
  156. [&使用超级旋风下载全部链接]
  157.   <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
  158. [Easy-WebPrint打印]
  159.   <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html, N/A>
  160. [Easy-WebPrint添加到打印列表]
  161.   <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html, N/A>
  162. [Easy-WebPrint预览]
  163.   <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html, N/A>
  164. [Easy-WebPrint高速打印]
  165.   <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html, N/A>
  166. [上传到QQ网络硬盘]
  167.   <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
  168. [导出到 Microsoft Office Excel(&X)]
  169.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  170. [添加到QQ自定义面板]
  171.   <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
  172. [添加到QQ表情]
  173.   <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
  174. [用QQ彩信发送该图片]
  175.   <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
复制代码

[ 本帖最后由 蓝色牛仔裤 于 2007-7-21 20:59 编辑 ]
蓝色牛仔裤
 楼主| 发表于 2007-7-21 20:58:51 | 显示全部楼层

  1. ==================================
  2. 正在运行的进程
  3. [PID: 584 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  4. [PID: 668 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  5. [PID: 692 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  6.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  7.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  8.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  9. [PID: 736 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  10. [PID: 748 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  11. [PID: 896 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  12. [PID: 992 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  13. [PID: 1092 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  14.     [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
  15. [PID: 1172 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  16. [PID: 1292 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  17. [PID: 1612 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  18.     [C:\WINDOWS\system32\CNMLM76.DLL]  [CANON INC., 1.90.2.20]
  19.     [C:\WINDOWS\system32\CNMLM6e.DLL]  [CANON INC., 1.80.2.50]
  20.     [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
  21.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD76.DLL]  [CANON INC., 1.90.2.20]
  22.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD6e.DLL]  [CANON INC., 1.80.2.50]
  23.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
  24. [PID: 1616 / Admin][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  25.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  26.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
  27.     [C:\Program Files\Common Files\Adobe\Shell\PSICON.DLL]  [Adobe Systems, Incorporated, 7.0]
  28.     [C:\Program Files\TENCENT\SSPlus\SAddr.dll]  [Tencent, 5, 0, 1, 17]
  29.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  30. [PID: 1884 / Admin][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3018]
  31.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  32.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  33. [PID: 1892 / Admin][C:\WINDOWS\system32\Rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  34.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  35.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  36. [PID: 1904 / Admin][C:\Program Files\360safe\safemon\360Tray.exe]  [奇虎网, 3, 5, 1, 1001]
  37.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  38.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  39.     [C:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 5, 0, 1001]
  40.     [C:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 5, 1, 1001]
  41.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  42.     [C:\Program Files\360safe\live.dll]  [360safe.com, 1, 0, 1, 1016]
  43. [PID: 1912 / Admin][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  44.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  45.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  46. [PID: 1920 / Admin][C:\WINDOWS\system32\DrvMon.exe]  [Alcor Micro, Corp., 1, 0, 0, 9]
  47.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  48.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  49. [PID: 1956 / Admin][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  50.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  51.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  52. [PID: 280 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  53. [PID: 1532 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  54. [PID: 2580 / Admin][D:\江门有线\登陆软件\JMCATVLogin.exe]  [江门有线广电网络中心, 3.0.0.14]
  55.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  56.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  57.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  58. [PID: 2716 / Admin][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  59.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  60.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  61.     [C:\Program Files\TENCENT\SSPlus\SAddr.dll]  [Tencent, 5, 0, 1, 17]
  62.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  63.     [C:\Program Files\Tencent\QQDownload\QQIEHelper02.dll]  [腾讯公司, 1, 1, 0, 5]
  64.     [C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL]  [Microsoft Corporation, 9.0.5510.0]
  65.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  66.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  67.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  68.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  69.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  70.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.299]
  71.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  72.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  73.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  74.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  75.     [C:\WINDOWS\system32\KIme.ime]  [金山软件公司, 1, 0, 0, 1]
  76.     [C:\PROGRA~1\COMMON~1\KingSoft\Extract\KSEngine.dll]  [, 1, 0, 0, 1]
  77.     [C:\PROGRA~1\COMMON~1\KingSoft\Extract\xfile.dll]  [N/A, ]
  78.     [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
  79.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  80.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  81. [PID: 1104 / Admin][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  82.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  83.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  84.     [C:\Program Files\TENCENT\SSPlus\SAddr.dll]  [Tencent, 5, 0, 1, 17]
  85.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  86.     [C:\Program Files\Tencent\QQDownload\QQIEHelper02.dll]  [腾讯公司, 1, 1, 0, 5]
  87.     [C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL]  [Microsoft Corporation, 9.0.5510.0]
  88.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  89.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  90.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  91.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  92.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  93.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.299]
  94.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  95.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  96.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  97.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  98.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  99.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  100. [PID: 3180 / Admin][C:\Documents and Settings\Admin\桌面\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  101.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  102.     [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 19]
  103.     [C:\WINDOWS\system32\IMSC40A.IME]  [Microsoft Corporation, 6.0.0.2527]
  104.     [C:\Documents and Settings\Admin\桌面\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

  105. ==================================
  106. 文件关联
  107. .TXT  Error. [C:\WINDOWS\notepad.exe %1]
  108. .EXE  OK. ["%1" %*]
  109. .COM  OK. ["%1" %*]
  110. .PIF  OK. ["%1" %*]
  111. .REG  OK. [regedit.exe "%1"]
  112. .BAT  OK. ["%1" %*]
  113. .SCR  OK. ["%1" /S]
  114. .CHM  Error. ["hh.exe" %1]
  115. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  116. .INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
  117. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  118. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  119. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  120. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  121. ==================================
  122. Winsock 提供者
  123. N/A

  124. ==================================
  125. Autorun.inf
  126. [C:\]
  127. [AutoRun]
  128. open=wscript.exe u.vbe
  129. shell\open\Command=wscript.exe u.vbe
  130. shell\explore\Command=wscript.exe u.vbe
  131. shell\find\Command=wscript.exe u.vbe
  132. [D:\]
  133. [AutoRun]
  134. open=wscript.exe u.vbe
  135. shell\open\Command=wscript.exe u.vbe
  136. shell\explore\Command=wscript.exe u.vbe
  137. shell\find\Command=wscript.exe u.vbe
  138. [E:\]
  139. [AutoRun]
  140. open=wscript.exe u.vbe
  141. shell\open\Command=wscript.exe u.vbe
  142. shell\explore\Command=wscript.exe u.vbe
  143. shell\find\Command=wscript.exe u.vbe
  144. [F:\]
  145. [AutoRun]
  146. open=wscript.exe u.vbe
  147. shell\open\Command=wscript.exe u.vbe
  148. shell\explore\Command=wscript.exe u.vbe
  149. shell\find\Command=wscript.exe u.vbe

  150. ==================================
  151. HOSTS 文件
  152. 127.0.0.1       localhost

  153. ==================================
  154. 进程特权扫描
  155. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1884, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
  156. 特殊特权被允许: SeDebugPrivilege [PID = 1904, C:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
  157. 特殊特权被允许: SeLoadDriverPrivilege [PID = 2580, D:\江门有线\登陆软件\JMCATVLOGIN.EXE]

  158. ==================================
  159. API HOOK
  160. RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  161. RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  162. RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  163. RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  164. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)

  165. ==================================
  166. 隐藏进程
  167. N/A

  168. ==================================


复制代码
solcroft
发表于 2007-7-22 00:24:23 | 显示全部楼层
典型的中了优盘病毒,杀毒后没清除autorun.inf文件的情况
把根目录下的autorun.inf删掉便行了,有很多方法,可以用windows explorer,cmd.exe,icesword...
蓝色牛仔裤
 楼主| 发表于 2007-7-22 16:30:17 | 显示全部楼层
清除autorun、清除autorun修改的有关注册表,已搞定,谢谢solcroft 了~
PS:我是牛仔裤。
微点卫士
发表于 2007-7-22 17:19:42 | 显示全部楼层

回复 #4 蓝色牛仔裤 的帖子

LZ玩无间道啊,我晕
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-24 00:26 , Processed in 0.149810 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表