查看: 1807|回复: 7
收起左侧

[已解决] 救救我的XP

 关闭 [复制链接]
sev7eno
发表于 2007-8-30 15:05:25 | 显示全部楼层 |阅读模式
GHOST了无数次(GHOST是以前刚装系统时备份的,没有问题),每次GHOST回来没过一小时IE内核就不知道被什么木马给叮上了,只要一用到基于IE内核的程序(我用的是GB)买咖啡就会报WEBGAME PSW 木马 ,然后GB就会变得很慢,现在只能用Opera上来发帖,可怜ING~情况如下
1.在WINDOWS文件夹下生成268.exe的东西,
2. 在Temporary Internet Files\Content.IE5\268[1].exe
3.在Temporary Internet Files\Content.IE5\KDE7C9IF\sysdown[1].exe
4.在Temporary Internet Files\Content.IE5\KDE7C9IF\CAEVCLIJ.exe
等....
好多~我都不清楚是什么,我自己设置了一些规则,下面是买咖啡的日志
2007-8-30        11:01:25        被行为阻挡规则阻挡         SEVEN\sev7eno        explorer.exe        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\Content.IE5\index.dat        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:读取
2007-8-30        11:01:40        被行为阻挡规则阻挡         SEVEN\sev7eno        explorer.exe        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\Content.IE5\index.dat        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:读取
2007-8-30        11:04:48        被行为阻挡规则阻挡         SEVEN\sev7eno        wangwang.exe        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\Content.IE5\index.dat        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:读取
2007-8-30        11:05:36        被行为阻挡规则阻挡         SEVEN\sev7eno        iexplore.exe        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\Content.IE5\index.dat        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:读取
2007-8-30        11:05:36        被行为阻挡规则阻挡         SEVEN\sev7eno        iexplore.exe        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\desktop.ini        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:读取
2007-8-30        11:06:51        被行为阻挡规则阻挡         SEVEN\sev7eno        gigaget.exe        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\Content.IE5\index.dat        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:读取

2007-8-30        13:40:37        被行为阻挡规则阻挡         SEVEN\sev7eno        greenbrowser.ex        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\Content.IE5\KDE7C9IF\sysdown[1].exe        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:创建
2007-8-30        13:40:37        被行为阻挡规则阻挡         SEVEN\sev7eno        greenbrowser.ex        C:\Documents and Settings\sev7eno\Local Settings\Temporary Internet Files\Content.IE5\KDE7C9IF\CAEVCLIJ.exe        禁止Temporary Internet Files文件夹创建EXE文件        已阻止的操作:创建
2007-8-30        13:40:39        被行为阻挡规则阻挡         SEVEN\sev7eno        greenbrowser.ex        C:\WINDOWS\286.exe        禁止在 Windows 文件夹中创建新文件 (.exe)        已阻止的操作:创建

各位帮帮忙~我用SREngPS 扫描了,日志如下,请各位帮分析看看到底我的XP怎么了~!

[ 本帖最后由 sev7eno 于 2007-8-30 15:12 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
sev7eno
 楼主| 发表于 2007-8-30 15:07:46 | 显示全部楼层
[CODE]

2007-08-30,14:36:06

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Runing Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><; nwiz.exe /install>  [NVIDIA Corporation]
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <SKYNET Personal FireWall><C:\PROGRA~1\SkyNet\Firewall\pfw.exe>  [广州众达天网技术有限公司]
    <ShStatEXE><"C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE>  [Network Associates, Inc.]
    <McAfeeUpdaterUI><"C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey>  [Network Associates, Inc.]
    <Network Associates Error Reporting Service><"C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe">  [Network Associates, Inc.]
    <Super Rabbit Memory><G:\Program Files\超级兔子魔法设置 V7.96 Final\MemDef.exe /LOAD>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player 6.4><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplayer2.inf,PerUserStub.NT>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
    <N/A><"C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player 8><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <Address Book 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <MSPY2002><; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]

==================================
Startup Folders
[Shortcut to Launcher]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Shortcut to Launcher.lnk --> G:\PROGRA~1\VAIO_L~1\Launcher.exe [Sony Corporation]><N>

==================================
Services
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[McAfee Framework 服务 / McAfeeFramework][Running/Auto Start]
  <C:\Program Files\Network Associates\Common Framework\FrameworkService.exe /ServiceStart><Network Associates, Inc.>
[Network Associates McShield / McShield][Running/Auto Start]
  <"C:\Program Files\Network Associates\VirusScan\Mcshield.exe"><Network Associates, Inc.>
[Network Associates Task Manager / McTaskManager][Running/Auto Start]
  <"C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe"><Network Associates, Inc.>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>

==================================
Drivers
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[NaiAvFilter1 / NaiAvFilter1][Running/Manual Start]
  <system32\drivers\naiavf5x.sys><Network Associates, Inc.>
[NaiAvTdi1 / NaiAvTdi1][Running/System Start]
  <system32\drivers\mvstdi5x.sys><Network Associates, Inc.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[SKNFW / SKNFW][Running/System Start]
  <\??\C:\WINDOWS\System32\Drivers\SKNFW.sys><N/A>
[SkyProcs / SkyProcs][Running/Manual Start]
  <\??\C:\PROGRA~1\SkyNet\Firewall\SkyProcs.sys><N/A>
[EntDrv51 / EntDrv51][Running/Manual Start]
  <\??\C:\WINDOWS\System32\drivers\EntDrv51.sys><Network Associates, Inc>

==================================
Browser Add-ons
[GigagetIEHelper Class]
  {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} <C:\WINDOWS\System32\gigagetbho_v10.dll, Giganology Inc.>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[&Radio]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, >
[WangWangObj Class]
  {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <D:\Program Files\淘宝网\淘宝旺旺\WangWangX4.dll, 阿里软件(中国)有限公司>
[&Download All by Gigaget]
  <C:\Program Files\Giganology\Gigaget\getallurl.htm, N/A>
[&Download by Gigaget]
  <C:\Program Files\Giganology\Gigaget\geturl.htm, N/A>
sev7eno
 楼主| 发表于 2007-8-30 15:10:41 | 显示全部楼层


==================================
Running Processes
[PID: 448 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 508 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 532 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 576 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
[PID: 588 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
[PID: 764 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
[PID: 816 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
[PID: 896 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
[PID: 1212 / sev7eno][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.7190]
    [C:\WINDOWS\System32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.7190]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
    [C:\WINDOWS\System32\nvshell.dll]  [NVIDIA Corporation, 6.14.10.10031]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\7-Zip\7-zip.dll]  [N/A, ]
[PID: 1312 / sev7eno][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.30]
[PID: 1356 / SYSTEM][C:\Program Files\Network Associates\Common Framework\FrameworkService.exe]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\nailog.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\Program Files\Network Associates\Common Framework\naXML.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\Program Files\Network Associates\Common Framework\naCmnLib.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\Program Files\Network Associates\Common Framework\applib.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\0804\AgentRes.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\Logging.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\InternetManager.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\naInet.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\Program Files\Network Associates\Common Framework\UserSpace.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\SecureFrameworkFactory.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\Management.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\cmalib.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\naPolicyManager.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\PsApi.dll]  [Microsoft Corporation, 4.00]
    [C:\Program Files\Network Associates\Common Framework\ScriptSubSys.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\UpdateSubSys.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\Scheduler.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\TCSubSys.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
[PID: 1392 / SYSTEM][C:\Program Files\Network Associates\VirusScan\Mcshield.exe]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.DLL]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\FTL.Dll]  [Network Associates, Inc., 8.0.0.133]
    [C:\Program Files\Network Associates\VirusScan\naiann.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\Common Framework\GenEvtInf.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\VirusScan\NaEventU.DLL]  [Network Associates, Inc., 8.0.0.342]
    [C:\Program Files\Network Associates\VirusScan\Res04\naEvtRes.dll]  [Network Associates, Inc., 8.0.0.342]
    [C:\Program Files\Network Associates\VirusScan\VSIDSvr.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\MCSCAN32.DLL]  [Network Associates, Inc., 4.3.20]
    [C:\Program Files\Network Associates\Common Framework\SecureFrameworkFactory.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\VirusScan\EntSrv.Dll]  [Network Associates, Inc, 8.0.0.240]
    [C:\WINDOWS\System32\msxml4.dll]  [Microsoft Corporation, 4.20.9818.0]
[PID: 1408 / SYSTEM][C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\SHUTIL.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\naiwmain.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\naicondl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\VsTskMgr.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\MIDUtil.Dll]  [Network Associates, Inc., 8.0.0.145]
    [C:\Program Files\Network Associates\VirusScan\BBCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\coptcpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\EmCfgCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\SEmalRes.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\Product.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\nvpcpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\ftcfg.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\OASCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\vsodscpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\ftl.dll]  [Network Associates, Inc., 8.0.0.133]
    [C:\Program Files\Network Associates\VirusScan\vsupdcpl.dll]  [Network Associates, Inc., 8.0.0.912]
[PID: 1460 / SYSTEM][C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe]  [Network Associates, Inc., 3.5.0.412]
    [C:\PROGRA~1\NETWOR~1\COMMON~1\nailog.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\PROGRA~1\NETWOR~1\COMMON~1\naCmnLib.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\PROGRA~1\NETWOR~1\COMMON~1\naXML.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\PROGRA~1\NETWOR~1\COMMON~1\0804\AgentRes.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\VirusScan\VsPlugin.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\WINDOWS\System32\EntApi.dll]  [Network Associates, Inc, 8.0.0.240]
[PID: 1504 / SYSTEM][C:\WINDOWS\System32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.7190]
[PID: 1572 / sev7eno][C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\SHUTIL.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\naiwmain.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\shstat.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\Product.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\RES04\Shutilrc.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\Graphics.dll]  [Network Associates, Inc., 8.0.0.912]
[PID: 1604 / sev7eno][C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\nailog.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\Program Files\Network Associates\Common Framework\naCmnLib.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\Program Files\Network Associates\Common Framework\naXML.dll]  [Network Associates, Inc., 3.5.0.474]
    [C:\Program Files\Network Associates\Common Framework\0804\UpdRes.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\0804\AgentRes.dll]  [Network Associates, Inc., 3.5.0.412]
    [C:\Program Files\Network Associates\Common Framework\SecureFrameworkFactory.dll]  [Network Associates, Inc., 3.5.0.412]
[PID: 1624 / sev7eno][C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe]  [Network Associates, Inc., 2.0.275.0]
[PID: 1684 / sev7eno][G:\Program Files\超级兔子魔法设置 V7.96 Final\MemDef.exe]  [, 4.0.0.0]
[PID: 1692 / sev7eno][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1892 / sev7eno][G:\Program Files\VAIO_Launcher\Launcher.exe]  [Sony Corporation, 1.4.11.07260]
    [G:\Program Files\VAIO_Launcher\Frn.dll]  [Sony Corporation, 1, 0, 1, 06100]
    [G:\Program Files\VAIO_Launcher\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [G:\Program Files\VAIO_Launcher\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [G:\Program Files\VAIO_Launcher\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [G:\Program Files\VAIO_Launcher\LauncherRes.dll]  [Sony Corporation, 1.0.00.14262]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 500 / sev7eno][D:\Program Files\淘宝网\淘宝旺旺\WangWang.exe]  [淘宝(中国)软件有限公司, 1, 9, 6, 1221]
    [D:\Program Files\淘宝网\淘宝旺旺\AliViewCtrl.dll]  [vline, 1, 0, 0, 1]
    [D:\Program Files\淘宝网\淘宝旺旺\VLNetwork.dll]  [, 1, 0, 0, 6]
    [D:\Program Files\淘宝网\淘宝旺旺\AliViewMedia.dll]  [vline, 1, 0, 0, 1]
    [D:\Program Files\淘宝网\淘宝旺旺\VideoCAP.dll]  [, 1, 0, 0, 4]
    [D:\Program Files\淘宝网\淘宝旺旺\VLAudio.dll]  [, 1, 0, 0, 4]
    [D:\Program Files\淘宝网\淘宝旺旺\JsmShow.dll]  [, 1, 0, 0, 3]
    [D:\Program Files\淘宝网\淘宝旺旺\ww_network.dll]  [, 1, 0, 1, 18]
    [D:\Program Files\淘宝网\淘宝旺旺\riched32.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\淘宝网\淘宝旺旺\RICHED20.dll]  [Microsoft Corporation, 5.30.23.1221]
    [D:\Program Files\淘宝网\淘宝旺旺\Ali_Res.DLL]  [N/A, ]
    [D:\Program Files\淘宝网\淘宝旺旺\WangWangX4.dll]  [阿里软件(中国)有限公司, 1, 0, 0, 1]
    [D:\Program Files\淘宝网\淘宝旺旺\RichOne.dll]  [淘宝(中国)软件有限公司, 1.0.0.1]
    [D:\Program Files\淘宝网\淘宝旺旺\TBProgress.dll]  [淘宝(中国)软件有限公司, 1.0.0.1]
    [C:\Program Files\Network Associates\VirusScan\scriptproxy.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [Network Associates, Inc., 4.3.20]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
sev7eno
 楼主| 发表于 2007-8-30 15:11:20 | 显示全部楼层

[PID: 844 / sev7eno][D:\Program Files\QQ\QQ.exe]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\CoralAssist.dll]  [Coral Team, 5.0.0 build 20060829]
    [D:\Program Files\QQ\CoralQQ.dll]  [Coral Team, 5.0.2 Build 20070716]
    [D:\Program Files\QQ\kql.dll]  [Coral Team, 5.0.2 build 20070703]
    [D:\Program Files\QQ\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\Program Files\QQ\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [D:\Program Files\QQ\mfc42.dll]  [Microsoft Corporation, 6.00.8665.0]
    [D:\Program Files\QQ\ipsearcher.dll]  [, 1.0.0.3]
    [D:\Program Files\QQ\QQBaseClassInDll.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQHelperDll.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\BasicCtrlDll.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\NoDisturbFilter.cqx]  [Coral Team, 1.0]
    [D:\Program Files\QQ\ConfigHotkey.cqx]  [Coral Team, 1.0]
    [D:\Program Files\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\Program Files\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\Program Files\QQ\QQAPI.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\Program Files\QQ\AutoReconnect.cqx]  [Coral Team, 1.0.0]
    [D:\Program Files\QQ\LoginCtrl.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\LoginCtrlRes.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQRes.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQMainFrame.dll]  [N/A, ]
    [D:\Program Files\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\QQ\CQQApplication.dll]  [N/A, ]
    [D:\Program Files\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\Program Files\QQ\NewSkin.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\HostingMgr.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\CameraDll.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\MailSummary.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\CoralHotkey.cqx]  [Coral Team, 1.0]
    [D:\Program Files\QQ\QQKnowledgeSearch.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQAllInOne.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
    [D:\Program Files\QQ\QQSpace.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\vbscript.dll]  [N/A, ]
    [D:\Program Files\QQ\aqing.dll]  [Microsoft Corporation, 5.6.0.8825]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [D:\Program Files\QQ\QQGroupMng.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQSettingCtrl.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQSysMsgMng.dll]  [N/A, ]
    [D:\Program Files\QQ\UserDefinedHead.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQPlugin.dll]  [N/A, ]
    [D:\Program Files\QQ\QQConfigPlugin.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQAvatar.dll]  [N/A, ]
    [D:\Program Files\QQ\QQCustomFace.dll]  [N/A, ]
    [D:\Program Files\QQ\LongConnection.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QRingMng.dll]  [N/A, ]
    [D:\Program Files\QQ\QQPet.dll]  [TENCENT, 7,0,365,1701]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\QQ\QQLiveQMng.dll]  [TENCENT, 7,0,365,1701]
    [C:\Program Files\Network Associates\VirusScan\scriptproxy.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [Network Associates, Inc., 4.3.20]
    [D:\Program Files\QQ\GroupConnection.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\BQQApplication.dll]  [N/A, ]
    [D:\Program Files\QQ\CommercesMng.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\Program Files\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 320]
    [D:\Program Files\QQ\QQSceneMng.dll]  [N/A, ]
    [D:\Program Files\QQ\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
    [D:\Program Files\QQ\QQZip.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\ImageOle.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\QQMagicFace.dll]  [TENCENT, 7,0,365,1701]
    [C:\WINDOWS\System32\SOGOUPY.IME]  [Sohu.com Inc., 1, 0, 2, 2]
    [D:\Program Files\QQ\QQFileTransfer.dll]  [TENCENT, 7,0,365,1701]
    [D:\Program Files\QQ\videodevice.dll]  [Tencent, 1, 6, 0, 2]
    [D:\Program Files\QQ\inplus.dll]  [Tencent, 1, 6, 0, 2]
    [C:\WINDOWS\System32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINDOWS\System32\devenum.dll]  [, ]
[PID: 932 / sev7eno][D:\Program Files\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [D:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1568 / sev7eno][C:\Program Files\Network Associates\VirusScan\mcconsol.exe]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\naiconsl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\SHUTIL.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\naiwmain.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\naicondl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\BBCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\coptcpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\EmCfgCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\SEmalRes.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\Product.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\nvpcpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\ftcfg.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\OASCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\vsodscpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\ftl.dll]  [Network Associates, Inc., 8.0.0.133]
    [C:\Program Files\Network Associates\VirusScan\vsupdcpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\RES04\Shutilrc.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\Graphics.dll]  [Network Associates, Inc., 8.0.0.912]
[PID: 3016 / sev7eno][G:\Program Files\Opera_9.10finalHH\Opera.exe]  [Opera Software, 8679]
    [G:\Program Files\Opera_9.10finalHH\Opera.dll]  [Opera Software, 8679]
    [G:\Program Files\Opera_9.10finalHH\program\plugins\NPSWF32.dll]  [, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\SOGOUPY.IME]  [Sohu.com Inc., 1, 0, 2, 2]
[PID: 1448 / sev7eno][G:\Program Files\GreenBrowser3.8.0212\GreenBrowser.exe]  [MoreQuick, 1, 0, 0, 0]
    [C:\Program Files\Network Associates\VirusScan\scriptproxy.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [Network Associates, Inc., 4.3.20]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3856 / sev7eno][G:\Bak\Inbox\TEMP\security\sreng-v2.5\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [G:\Bak\Inbox\TEMP\security\sreng-v2.5\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
Process Privileges Scan
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1572, C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\SHSTAT.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1604, C:\PROGRAM FILES\NETWORK ASSOCIATES\COMMON FRAMEWORK\UPDATERUI.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1624, C:\PROGRAM FILES\COMMON FILES\NETWORK ASSOCIATES\TALKBACK\TBMON.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1684, G:\PROGRAM FILES\超级兔子魔法设置 V7.96 FINAL\MEMDEF.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1892, G:\PROGRAM FILES\VAIO_LAUNCHER\LAUNCHER.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 500, D:\PROGRAM FILES\淘宝网\淘宝旺旺\WANGWANG.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 932, D:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1568, C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\MCCONSOL.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 3016, G:\PROGRAM FILES\OPERA_9.10FINALHH\OPERA.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1448, G:\PROGRAM FILES\GREENBROWSER3.8.0212\GREENBROWSER.EXE]

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


[/CODE]
zqa224
发表于 2007-8-30 15:37:57 | 显示全部楼层
不会分析报告阿!!但是遇到这种情况过,你ghost回来后,用资源管理器打开其他盘,注意先把“系统文件隐藏”关了并显示所有文件,把其他盘里的自启动文件都删了再试试阿!!
强音
发表于 2007-9-2 14:20:37 | 显示全部楼层
估计是GHOST的系统本来就不干净,要稳定的系统还是格式化重新安装比较好!抛弃GHOST,找个口碑好的安装版系统盘来装吧!
伊の星
发表于 2007-9-2 17:14:02 | 显示全部楼层
楼主请将sreng扫出来的报告再传一次,上面的不完整。
azuresy
发表于 2007-9-2 17:21:28 | 显示全部楼层
备份的GHOST文件也被感染了,重装吧~
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-22 00:13 , Processed in 0.166991 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表