查看: 1827|回复: 7
收起左侧

高手们....来看看呀..!!((报告已贴上,版主来看看!!))

[复制链接]
on_the_way
头像被屏蔽
发表于 2007-10-9 19:13:20 | 显示全部楼层 |阅读模式
昨天晚上...我插入了一个U盘...不料U盘中有毒...系统自动修改时间...卡巴被干掉了...弹出几个窗口后...几秒钟后电脑也死了(不能动)...郁闷呀...真没想到卡巴也有如此致命的弱点...心想还好我有GHOST备份...GHOST还原C盘后发现一个问题..
如下:  
       当打开我的电脑,如在本地磁盘C按左键什么事也没有,但是按右键时就会:首先没有出现显示...等几十秒后自动把我的电脑窗口关闭了...
                                       补充...有提示出现drwtsn32.exe和explorer.exe错误对话框!!

这是什么回事?其他本地磁盘(D\E\F)也是这样,但是双键进入了本地磁盘如C,选择文件\文件夹按右键能正常显示出来,同样操作其他本地磁盘(D\E\F)都没有问题....
     郁闷呀...我的备份是一个正常系统...怎么还原出来的是有问题的呢...以前系统出问题也是那样操作还原...为何这次就出现这样的问题...
    请问我中了什么毒呀...怎样解决本地磁盘(C\D\E\F)右键不能显示自动关闭的问题....为何GHOST还原C盘还有这种情况??

[ 本帖最后由 on_the_way 于 2007-10-10 20:30 编辑 ]
mds
发表于 2007-10-9 19:16:53 | 显示全部楼层
用置顶工具帖里的usbcleaner查杀下看看!
还有问题用SREng扫个报告贴上来
danger
发表于 2007-10-9 19:26:02 | 显示全部楼层
用usb专杀杀一次
河北鬼鬼
发表于 2007-10-9 19:43:04 | 显示全部楼层
去找U盘专杀吧.卡巴唯一缺点就是自我保护能力弱点
on_the_way
头像被屏蔽
 楼主| 发表于 2007-10-9 19:59:37 | 显示全部楼层

报告

usbcleaner查杀没有毒....SREng的扫描:          我是菜鸟不知道怎样修复...帮帮忙!!谢谢!!
  1. 2007-10-09,19:52:03
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.       [(Verified)Microsoft Windows Publisher]
  18.       []
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  20.     <>  [N/A]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  22.     <"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  23.       [(Verified)Microsoft Windows Publisher]
  24.       [(Verified)Microsoft Windows Publisher]
  25.     <"D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
  26.     <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  27.       [(Verified)Microsoft Corporation]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.       [(Verified)Microsoft Windows Publisher]
  30.       [(Verified)Microsoft Windows Publisher]
  31. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  32.     <>  [N/A]
  33. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  34.       [(Verified)Microsoft Windows Publisher]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  36.     <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}>  [Beijing Rising Technology Co., Ltd.]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  38.       [(Verified)Microsoft Windows Component Publisher]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  40.       [Kaspersky Lab]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  42.     <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  44.     <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  46.     <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  47. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  48.     <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  49. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  50.       [(Verified)Microsoft Corporation]
  51. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  52.       [(Verified)Microsoft Windows Publisher]
  53. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  54.       [(Verified)Microsoft Windows Component Publisher]
  55. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  56.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  57. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  58.       [Microsoft Corporation]
  59. ==================================
  60. 启动文件夹
  61. N/A
  62. ==================================
  63. 服务
  64. [Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  65.   <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe">
  66. [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  67.   
  68. [ATI Smart / ATI Smart][Stopped/Auto Start]
  69.   <>
  70. [Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
  71.   <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe">
  72. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  73.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r>
  74. [Windows Presentation Foundation Font Cache 3.0.0.0 / FontCache3.0.0.0][Stopped/Manual Start]
  75.   
  76. [Human Interface Device Access / HidServ][Stopped/Disabled]
  77.   %SystemRoot%\System32\hidserv.dll>
  78. [Windows CardSpace / idsvc][Stopped/Manual Start]
  79.   <"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe">
  80. [NBService / NBService][Stopped/Manual Start]
  81.   
  82. [Net.Tcp Port Sharing Service / NetTcpPortSharing][Stopped/Disabled]
  83.   <"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe">
  84. [NMIndexingService / NMIndexingService][Stopped/Manual Start]
  85.   <"C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe">
  86. [Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  87.   
  88. [Rising Personal Firewall Service / RfwService][Running/Auto Start]
  89.   
  90. [StarWind iSCSI Service / StarWindService][Stopped/Auto Start]
  91.   
  92. [StyleXPService / StyleXPService][Stopped/Auto Start]
  93.   <"C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"><>
  94. ==================================
  95. 驱动程序
  96. [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  97.   
  98. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  99.   
  100. [ati2mtag / ati2mtag][Running/Manual Start]
  101.   
  102. [BaseTDI / BaseTDI][Running/Auto Start]
  103.   <\??\C:\WINDOWS\system32\drivers\basetdi.sys>
  104. [10Moons TV Baby, WDM Video Captures / Cap7134][Running/Manual Start]
  105.   
  106. [Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
  107.   
  108. [HookUrl / HookUrl][Running/Auto Start]
  109.   <\??\D:\Program Files\Rising\Rfw\HookUrl.sys>
  110. [kl1 / kl1][Running/Boot Start]
  111.   <\SystemRoot\system32\drivers\kl1.sys>
  112. [klif / klif][Running/System Start]
  113.   <\??\C:\WINDOWS\system32\drivers\klif.sys>
  114. [mProcRs / mProcRs][Running/Auto Start]
  115.   <\??\d:\program files\rising\rfw\mProcRs.sys>
  116. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  117.   
  118. [RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  119.   <\SystemRoot\system32\drivers\RsBoot.sys>
  120. [RsFwDrv / RsFwDrv][Running/Auto Start]
  121.   <\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys>
  122. [Secdrv / Secdrv][Stopped/Manual Start]
  123.   
  124. [Intel (R) System Management BIOS Service / SMBios][Running/Manual Start]
  125.   
  126. [sptd / sptd][Running/Boot Start]
  127.   <\SystemRoot\System32\Drivers\sptd.sys>
  128. [StyleXPHelper / StyleXPHelper][Running/System Start]
  129.   <\??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe>
  130. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  131.   
  132. ==================================
  133. 浏览器加载项
  134. [ThunderAtOnce Class]
  135.   {01443AEC-0FD1-40fd-9C87-E93D1494C233}
  136. [Thunder Browser Helper]
  137.   {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3}
  138. [Adobe PDF Reader Link Helper]
  139.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
  140. [Web反病毒保护]
  141.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}
  142. [信息检索(&R)]
  143.   {92780B25-18CC-41C8-B9BE-3C9C571A8263}
  144. [卡卡上网安全助手]
  145.   {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
  146. [金山快译(&K)]
  147.   {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C}
  148. [WUWebControl Class]
  149.   {6414512B-B978-451D-A0D8-FCFDF33E833C}
  150. [Shockwave Flash Object]
  151.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  152. [ThunderAtOnce Class]
  153.   {01443AEC-0FD1-40FD-9C87-E93D1494C233}
  154. [Thunder Browser Helper]
  155.   {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3}
  156. [Adobe PDF Reader Link Helper]
  157.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
  158. [Windows Genuine Advantage Validation Tool]
  159.   {17492023-C23A-453E-A040-C7C580BBF700}
  160. [Thunder Agent Class]
  161.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE}
  162. [WUWebControl Class]
  163.   {6414512B-B978-451D-A0D8-FCFDF33E833C}
  164. [金山快译(&K)]
  165.   {6C3797D2-3FEF-4CD4-B654-D3AE55B4128C}
  166. [SearchAssistantOC]
  167.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  168. [Shockwave Flash Object]
  169.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  170. [卡卡上网安全助手]
  171.   {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
  172. [使用迅雷下载]
  173.   
  174. [使用迅雷下载全部链接]
  175.   
  176. [导出到 Microsoft Office Excel(&X)]
  177.   
  178. [添加到QQ表情]
  179.   
  180. ==================================
  181. 正在运行的进程
  182. [PID: 696 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  183. [PID: 780 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  184. [PID: 804 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  185.     [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4107]
  186.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  187. [PID: 848 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  188. [PID: 860 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  189. [PID: 1028 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4107]
  190.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2495]
  191. [PID: 1052 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  192. [PID: 1136 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  193. [PID: 1244 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  194. [PID: 1408 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  195. [PID: 1480 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  196. [PID: 1524 / SYSTEM][d:\program files\rising\rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 35]
  197.     [d:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
  198.     [d:\program files\rising\rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
  199.     [d:\program files\rising\rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
  200.     [d:\program files\rising\rfw\psapi.dll]  [Microsoft Corporation, 4.00]
  201.     [d:\program files\rising\rfw\MonDrv.dll]  [rs, 1, 0, 0, 4]
  202.     [d:\program files\rising\rfw\ProcLib.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
  203.     [d:\program files\rising\rfw\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
  204. [PID: 1660 / Administrator][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4107]
  205.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2495]
  206. [PID: 1864 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  207.     [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
  208.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
  209.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll]  [Microsoft Corporation, 6.0.5824.16384 (winmain(wmbla).060911-0725)]
  210. [PID: 2016 / Administrator][d:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
  211.     [d:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
  212.     [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
  213.     [d:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
  214.     [d:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
  215.     [d:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
  216. [PID: 1604 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  217. [PID: 1432 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  218. [PID: 192 / Administrator][D:\Program Files\Tencent\TT\TTraveler.exe]  [Tencent, 3, 8, 308, 201]
  219.     [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]
  220.     [D:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  [腾讯公司, 1, 1, 0, 5]
  221.     [D:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  [, 1, 0, 0, 3]
  222.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  223.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  224.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  225.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  226.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
  227.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  228.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  229.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  230.     [D:\Program Files\Tencent\TT\TTNetFavor.dll]  [N/A, ]
  231.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  232.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  233.     [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
  234.     [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
  235.     [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
  236.     [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 1]
  237.     [C:\WINDOWS\system32\dllMergeDict.dll]  [N/A, ]
  238.     [c:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
  239. [PID: 2000 / Administrator][J:\下载\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  240.     [J:\下载\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  241.     [J:\下载\sreng2\Plugins\NTFSTREAM.SRE]  [Smallfrogs Studio, 1, 0, 0, 5]
  242. [PID: 2704 / Administrator][C:\WINDOWS\system32\drwtsn32.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
  243. [PID: 1808 / Administrator][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
  244.     [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]
  245. ==================================
  246. 文件关联
  247. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  248. .EXE  OK. ["%1" %*]
  249. .COM  OK. ["%1" %*]
  250. .PIF  OK. ["%1" %*]
  251. .REG  OK. [regedit.exe "%1"]
  252. .BAT  OK. ["%1" %*]
  253. .SCR  OK. ["%1" /S]
  254. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  255. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  256. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  257. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  258. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  259. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  260. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  261. ==================================
  262. Winsock 提供者
  263. N/A
  264. ==================================
  265. Autorun.inf
  266. N/A
  267. ==================================
  268. HOSTS 文件
  269. 127.0.0.1       localhost
  270. ==================================
  271. 进程特权扫描
  272. 特殊特权被允许: SeLoadDriverPrivilege [PID = 192, D:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE]
  273. ==================================
  274. API HOOK
  275. RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  276. RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  277. RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  278. RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  279. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  280. ==================================
  281. 隐藏进程
  282. N/A
  283. ==================================
复制代码
on_the_way
头像被屏蔽
 楼主| 发表于 2007-10-11 08:52:09 | 显示全部楼层
啊................ ,没有人知道吗?
yaker
发表于 2007-10-11 10:09:43 | 显示全部楼层
用KIS7.0.125吧,下载个USBKILLER做全盘扫描,效果比USBCLEANER好。
on_the_way
头像被屏蔽
 楼主| 发表于 2007-10-11 15:18:00 | 显示全部楼层
简单说怎样处理由病毒引起的本地磁盘(C\D\E\F)右键不能显示自动关闭窗口的问题
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-3-19 14:06 , Processed in 0.130585 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表