查看: 5863|回复: 12
收起左侧

Trojan-Spy.Win32.delf.ul怎么杀不掉啊?在线求助!

[复制链接]
ltyzy2000
发表于 2007-3-9 13:05:37 | 显示全部楼层 |阅读模式
不知道怎么中了木马Trojan-Spy.Win32.delf.ul,卡巴一直报,杀完之后等一会又开始报了,把IE_HElP.dll强行删除后重启也不行。请问怎么回事?怎么删掉啊?
wangjay1980
发表于 2007-3-9 13:15:59 | 显示全部楼层
扫个报告看看
ltyzy2000
 楼主| 发表于 2007-3-9 13:29:57 | 显示全部楼层
Logfile of HijackThis v1.99.1
Scan saved at 13:29:13, on 2007-3-9
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\MSN Messenger\usnsvc.exe
D:\eMule\emule.exe
D:\QQ\QQ.exe
D:\QQ\TIMPlatform.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Maxthon\Maxthon.exe
d:\WinRAR\WinRAR.exe
C:\DOCUME~1\兰天一\LOCALS~1\Temp\Rar$EX00.469\HijackThis.exe

O2 - BHO: (no name) - {7F9FBFAD-C171-4B2B-AC7E-1EA1119C938D} - C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\MICROS~1\APPLIC~1\IE_Help.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [kis] "D:\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [DAEMON Tools-2052] ; "D:\D-Tools\daemon.exe"  -lang 2052
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] ; HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [WebThunder] ; d:\WebThunder\WebThunder.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: 腾讯QQ.lnk = D:\QQ\QQ.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: 木马杀客2007.Lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用BitComet下载 - res://D:\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &使用迅雷下载 - D:\Thunder\Program\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Thunder\Program\getallurl.htm
O8 - Extra context menu item: 使用Web迅雷下载 - d:\WebThunder\GetUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 导出当前页到超星阅览器(&A) - C:\Program Files\SSREADER36\ss_all.htm
O8 - Extra context menu item: 导出选中部分到超星阅览器(&S) - C:\Program Files\SSREADER36\ss_select.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Thunder\Thunder.exe
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\浩方对战平台\GameClient.exe
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra 'Tools' menuitem: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra 'Tools' menuitem: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra 'Tools' menuitem: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/wind ... e.cab?1173057692015
O17 - HKLM\System\CCS\Services\Tcpip\..\{013015D8-F502-4312-A381-074B0A1EC695}: NameServer = 202.196.64.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{013015D8-F502-4312-A381-074B0A1EC695}: NameServer = 202.196.64.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{013015D8-F502-4312-A381-074B0A1EC695}: NameServer = 202.196.64.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: D:\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: 卡巴斯基互联网安全套装 6.0 (AVP) - Unknown owner - D:\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
ltyzy2000
 楼主| 发表于 2007-3-9 13:31:02 | 显示全部楼层
我把前两项的注册表删了后,等一会又出来了
ltyzy2000
 楼主| 发表于 2007-3-9 13:40:33 | 显示全部楼层
没有人看吗?
wangjay1980
发表于 2007-3-9 15:21:47 | 显示全部楼层
用这个扫

sreng2.zip

477.1 KB, 下载次数: 193

ltyzy2000
 楼主| 发表于 2007-3-9 17:40:34 | 显示全部楼层


  1. 2007-03-09,17:35:56

  2. System Repair Engineer 2.3.13.690
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600)
  5. - 管理权限用户 - 完整功能

  6. 以下内容被选中:
  7.     所有的启动项目(包括注册表、启动文件夹、服务等)
  8.     浏览器加载项
  9.     正在运行的进程(包括进程模块信息)
  10.     文件关联
  11.     Winsock 提供者
  12.     Autorun.inf
  13.     HOSTS 文件


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
  18.     <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [(Verified)Microsoft Corporation]
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  20.     <load><>  [N/A]
  21.     <run><>  [N/A]
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  23.     <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
  24.     <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
  25.     <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
  26.     <kis><"D:\Kaspersky Internet Security 6.0\avp.exe">  [Kaspersky Lab]
  27.     <DAEMON Tools-2052><; "D:\D-Tools\daemon.exe"  -lang 2052>  [DAEMON'S HOME]
  28.     <High Definition Audio Property Page Shortcut><; HDAShCut.exe>  [(Verified)Windows (R) Server 2003 DDK provider]
  29.     <SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe>  [(Verified)Analog Devices, Inc.]
  30.     <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
  31.     <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [N/A]
  32.     <WebThunder><; d:\WebThunder\WebThunder.exe>  [深圳市迅雷网络技术有限公司]
  33. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  34.     <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
  35.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
  36. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  37.     <AppInit_DLLs><D:\KASPER~1.0\adialhk.dll>  [Kaspersky Lab]
  38. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  39.     <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  41.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]

  42. ==================================
  43. 启动文件夹
  44. [Adobe Reader Speed Launch]
  45.   <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> D:\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><H>
  46. [木马杀客2007]
  47.   <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\木马杀客2007.Lnk --> D:\木马杀客\木马杀客\mmsk.exe [N/A]><H>
  48. [腾讯QQ]
  49.   <C:\Documents and Settings\兰天一\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\QQ\QQ.exe [TENCENT]><H>

  50. ==================================
  51. 服务
  52. [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  53.   <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
  54. [卡巴斯基互联网安全套装 6.0 / AVP][Running/Auto Start]
  55.   <"D:\Kaspersky Internet Security 6.0\avp.exe" -r><Kaspersky Lab>
  56. [Human Interface Device Access / HidServ][Stopped/Disabled]
  57.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  58. [Visual Studio Analyzer RPC bridge / Visual Studio Analyzer RPC bridge][Stopped/Manual Start]
  59.   <D:\Visual FoxPro\common\Tools\VS-Ent98\Vanalyzr\varpc.exe><Microsoft Corporation>

  60. ==================================
  61. 驱动程序
  62. [ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
  63.   <system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
  64. [AEAudio Service / AEAudioService][Running/Manual Start]
  65.   <system32\drivers\AEAudio.sys><Andrea Electronics Corporation>
  66. [AliIde / AliIde][Running/Boot Start]
  67.   <\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
  68. [Asushwio / Asushwio][Stopped/Manual Start]
  69.   <\??\C:\WINDOWS\system32\drivers\Asushwio.sys><N/A>
  70. [ati2mtag / ati2mtag][Running/Manual Start]
  71.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  72. [d347bus / d347bus][Running/Boot Start]
  73.   <\SystemRoot\system32\DRIVERS\d347bus.sys><>
  74. [d347prt / d347prt][Running/Boot Start]
  75.   <\SystemRoot\System32\Drivers\d347prt.sys><>
  76. [Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Stopped/Manual Start]
  77.   <system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
  78. [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  79.   <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
  80. [kl1 / kl1][Running/Boot Start]
  81.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  82. [klif / klif][Running/System Start]
  83.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  84. [m5288 / m5288][Running/Boot Start]
  85.   <\SystemRoot\system32\DRIVERS\m5288.sys><ULi Electronics Inc.>
  86. [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start]
  87.   <system32\DRIVERS\ASACPI.sys><>
  88. [npkcrypt / npkcrypt][Running/Auto Start]
  89.   <\??\D:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  90. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  91.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  92. [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  93.   <system32\DRIVERS\Rtenicxp.sys><Realtek Semiconductor Corporation>
  94. [Secdrv / Secdrv][Stopped/Manual Start]
  95.   <system32\DRIVERS\secdrv.sys><N/A>
  96. [SenFilt Service / SenFiltService][Running/Manual Start]
  97.   <system32\drivers\Senfilt.sys><Sensaura>
  98. [Sentinel / Sentinel][Running/Auto Start]
  99.   <\SystemRoot\System32\Drivers\SENTINEL.SYS><Rainbow Technologies, Inc.>
  100. [TCP/IP Protocol Driver / Tcpip][Running/System Start]
  101.   <system32\DRIVERS\tcpip.sys><Microsoft Corporation>

  102. ==================================
  103. 浏览器加载项
  104. [启动迅雷5]
  105.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
  106. [浩方对战平台]
  107.   {0A155D3C-68E2-4215-A47A-E800A446447A} <D:\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
  108. [Web反病毒保护]
  109.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab>
  110. [信息检索(&R)]
  111.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  112. [启动Web迅雷]
  113.   {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
  114. [Windows Genuine Advantage Validation Tool]
  115.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
  116. [WUWebControl Class]
  117.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  118. [WebThunder Browser Helper]
  119.   {00000AAA-A363-466E-BEF5-9BB68697AA7F} <d:\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
  120. [Windows Genuine Advantage Validation Tool]
  121.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
  122. [HTML Document]
  123.   {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
  124. [Microsoft Office Control]
  125.   {4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} <D:\MICROS~2\OFFICE11\AUTHZAX.DLL, Microsoft Corporation>
  126. [WUWebControl Class]
  127.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  128. [Windows Media Player]
  129.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  130. [Thunder Browser Helper]
  131.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Thunder\ComDlls\XunLeiBHO_002.dll, N/A>
  132. [SearchAssistantOC]
  133.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  134. [Shockwave Flash Object]
  135.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  136. [&使用BitComet下载]
  137.   <res://D:\BitComet\BitComet.exe/AddLink.htm, N/A>
  138. [&使用迅雷下载]
  139.   <D:\Thunder\Program\geturl.htm, N/A>
  140. [&使用迅雷下载全部链接]
  141.   <D:\Thunder\Program\getallurl.htm, N/A>
  142. [上传到QQ网络硬盘]
  143.   <, N/A>
  144. [使用Web迅雷下载]
  145.   <d:\WebThunder\GetUrl.htm, N/A>
  146. [使用Web迅雷下载全部链接]
  147.   <, N/A>
  148. [导出到 Microsoft Office Excel(&X)]
  149.   <res://D:\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  150. [导出当前页到超星阅览器(&A)]
  151.   <C:\Program Files\SSREADER36\ss_all.htm, N/A>
  152. [导出选中部分到超星阅览器(&S)]
  153.   <C:\Program Files\SSREADER36\ss_select.htm, N/A>
  154. [添加到QQ自定义面板]
  155.   <, N/A>
  156. [添加到QQ表情]
  157.   <, N/A>
  158. [用QQ彩信发送该图片]
  159.   <, N/A>

  160. ==================================
  161. 正在运行的进程
  162. [PID: 684][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  163. [PID: 744][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  164. [PID: 768][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  165.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  166.     [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4117]
  167.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  168. [PID: 812][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  169. [PID: 824][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  170.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  171. [PID: 980][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4117]
  172.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2497]
  173.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  174. [PID: 1004][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  175.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  176. [PID: 1084][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  177.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  178.     [D:\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  179. [PID: 1252][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  180.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  181. [PID: 1328][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  182.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  183. [PID: 1532][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4117]
  184.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  185.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2497]
  186. [PID: 1652][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  187.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  188.     [D:\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  189.     [d:\WinRAR\rarext.dll]  [N/A, N/A]
  190.     [D:\Kaspersky Internet Security 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
  191. [PID: 1728][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  192.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  193.     [C:\WINDOWS\system32\pdfmon.dll]  [N/A, N/A]
  194.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  [Windows (R) 2000 DDK provider, 5.00.2195.1620]
  195.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  196. [PID: 1968][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  197.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  198. [PID: 348][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
  199. [PID: 2152][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  200.     [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  201. [PID: 2520][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [N/A, N/A]
  202.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  203.     [D:\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  204. [PID: 3508][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  205.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  206.     [D:\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  207.     [D:\Kaspersky Internet Security 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  208.     [D:\Kaspersky Internet Security 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  209.     [D:\Kaspersky Internet Security 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  210.     [D:\Kaspersky Internet Security 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  211.     [D:\Kaspersky Internet Security 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
  212.     [d:\kaspersky internet security 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  213.     [d:\kaspersky internet security 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  214.     [d:\kaspersky internet security 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  215.     [d:\kaspersky internet security 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  216.     [d:\kaspersky internet security 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  217. [PID: 4012][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  218.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  219.     [D:\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  220.     [D:\Kaspersky Internet Security 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  221.     [D:\Kaspersky Internet Security 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  222.     [D:\Kaspersky Internet Security 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  223.     [D:\Kaspersky Internet Security 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  224.     [D:\Kaspersky Internet Security 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
  225.     [d:\kaspersky internet security 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  226.     [d:\kaspersky internet security 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  227.     [d:\kaspersky internet security 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  228.     [d:\kaspersky internet security 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  229.     [d:\kaspersky internet security 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  230.     [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
  231.     [D:\Thunder\Components\VPShell\RealMediaSplitter.ax]  [Gabest, 1, 0, 1, 0]
  232. [PID: 2584][d:\WinRAR\WinRAR.exe]  [N/A, N/A]
  233.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  234.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  235. [PID: 3140][C:\DOCUME~1\兰天一\LOCALS~1\Temp\Rar$EX01.891\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
  236.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  237.     [D:\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]

  238. ==================================
  239. 文件关联
  240. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  241. .EXE  OK. ["%1" %*]
  242. .COM  OK. ["%1" %*]
  243. .PIF  OK. ["%1" %*]
  244. .REG  OK. [regedit.exe "%1"]
  245. .BAT  OK. ["%1" %*]
  246. .SCR  OK. ["%1" /S]
  247. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  248. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  249. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  250. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  251. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  252. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  253. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  254. ==================================
  255. Winsock 提供者
  256. N/A

  257. ==================================
  258. Autorun.inf
  259. N/A

  260. ==================================
  261. HOSTS 文件
  262. 127.0.0.1       localhost

  263. ==================================
  264. API HOOK
  265. 警告!System Repair Engineer 提醒
  266. 你下面的函数内容与预期值不符,他
  267. 们可能被一些恶意的软件所修改:
  268. RVA  错误: LoadLibraryA
  269. RVA  错误: LoadLibraryExA
  270. RVA  错误: LoadLibraryExW
  271. RVA  错误: LoadLibraryW

  272. ==================================


复制代码
ltyzy2000
 楼主| 发表于 2007-3-9 17:41:15 | 显示全部楼层
多谢!!!!
wangjay1980
发表于 2007-3-9 23:40:13 | 显示全部楼层
看报告没有什么问题,你可以用这个清理一下

arswp_1[1].6.0.rar

516.92 KB, 下载次数: 200

风雪
发表于 2007-3-10 17:12:32 | 显示全部楼层
O2 - BHO: (no name) - {7F9FBFAD-C171-4B2B-AC7E-1EA1119C938D} - C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\MICROS~1\APPLIC~1\IE_Help.dll
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
修复一下。
C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\MICROS~1\APPLIC~1\IE_Help.dll删除。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-22 16:33 , Processed in 0.147598 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表