查看: 2890|回复: 3
收起左侧

[讨论] 卡巴无法运行,请高手帮忙看下扫描日志

[复制链接]
x361945
发表于 2007-4-17 20:53:55 | 显示全部楼层 |阅读模式
卡巴无法运行,sre和hijack本来也无法运行,表现为双击之后无任何反因,但其他exe文件可以运行,后来更改了文件目录名之后可以运行,于是复制了日志请高手帮忙看下.
先是sre的日志
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><G:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
    <1MJPMIG__><; G:\WINDOWS\IMEINPUTS.EXE>  []
    <MSMSGS><; "G:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
    <MsnMsgr><; >  [N/A]
    <sys001><; G:\WINDOWS\rundll32.exe>  [N/A]
    <system><; c:\SVCHOST.exe>  [N/A]
    <WeatherBug><; C:\Program Files\AWS\WeatherBug\WeatherBug.exe>  [(Verified)WeatherBug]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Logitech Utility><LOGI_MWX.EXE>  [Logitech Inc.]
    <TkBellExe><; "G:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
    <MSConfig><G:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto>  [(Verified)Microsoft Windows XP Publisher]
    <ATICCC><; "G:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe">  [N/A]
    <ATIPTA><; G:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [N/A]
    <CloneCDTray><; >  [N/A]
    <DAEMON Tools-1033><; "G:\Program Files\D-Tools\daemon.exe"  -lang 1033>  [DAEMON'S HOME]
    <defender><; C:\\dfndrff_8.exe>  [N/A]
    <exp1orer><; G:\WINDOWS\System32\exp1orer.exe>  [N/A]
    <fenglei><; D:\software\flmpc\fengleiLive.exe>  [风雷影音工作室]
    <IMJPMIG8.1><; "G:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  [N/A]
    <keyboard><; C:\\kybrdff_8.exe>  [N/A]
    <Messager.exe><; G:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <Messenger.exe><; G:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <msnappau><; "G:\Program Files\MSN Apps\Updater\01.02.3000.1001\zh-hk\msnappau.exe">  [Microsoft Corporation]
    <NeroFilterCheck><; G:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <newname><; C:\\nwnmff_8.exe>  [N/A]
    <NvCplDaemon><; RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <nwiz><; nwiz.exe /install>  [NVIDIA Corporation]
    <PHIME2002A><; G:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><; G:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <Realplayer.exe><; G:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <SoundMan><; SOUNDMAN.EXE>  [(Verified)Microsoft Windows XP Publisher]
    <SunJavaUpdateSched><; G:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe>  []
    <WangWang><; >  [N/A]
    <WinampAgent><; "D:\software\Winamp\Winampa.exe">  []
    <zcom><; \zPlatform.exe MIN>  [N/A]
    <_rx><; G:\WINDOWS\command\rundll32.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><G:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><KB235780M.LOG,G:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{220BF032-F032-20B1-3220-0320B03220B1}><G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll>  []
    <{1B4E3287-2C14-F46E-89D0-AADD240C8576}><G:\WINDOWS\System32\dl23qso.dll>  []
    <{274B93C2-A6DF-485F-8576-AB0653134A76}><G:\WINDOWS\System32\dl32qso.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><G:\WINDOWS\System32\klogon.dll>  [Kaspersky Lab]
==================================
启动文件夹
[Logitech Desktop Messenger]
  <G:\Documents and Settings\All Users\「开始」菜单\程序\启动\Logitech Desktop Messenger.lnk --> D:\software\DESKTO~1\8876480\Program\LDMConf.exe [Logitech]><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <G:\WINDOWS\System32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
  <G:\WINDOWS\system32\ati2sgag.exe><>
[卡巴斯基互联网安全套装6.0个人版 / AVP][Stopped/Disabled]
  <"G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <G:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Network Monitor / Network Monitor][Stopped/Disabled]
  <G:\Program Files\Network Monitor\netmon.exe service><N/A>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Disabled]
  <G:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[PDEngine / PDEngine][Stopped/Manual Start]
  <G:\Program Files\Raxco\PerfectDisk\PDEngine.exe><Raxco Software, Inc.>
[PDScheduler / PDSched][Stopped/Manual Start]
  <G:\Program Files\Raxco\PerfectDisk\PDSched.exe><Raxco Software, Inc.>
[Remote Access Auto Connection Manager / RasAuto][Running/Auto Start]
  <G:\WINDOWS\System32\svchost.exe -k netsvcs-->G:\WINDOWS\System32\rasaute_2.dll><N/A>
[Remote Procedure Call System(RPCS) / RpcS][Running/Auto Start]
  <G:\WINDOWS\System32\RpcS.exe><Microsoft Corporation>
[RtmoteAccess / RtmoteAccess][Stopped/Disabled]
  <G:\WINDOWS\windowse><N/A>
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ati2mtag / ati2mtag][Running/Manual Start]
  <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[d347bus / d347bus][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\d347prt.sys><>
[ElbyCDFL / ElbyCDFL][Running/Manual Start]
  <System32\Drivers\ElbyCDFL.sys><SlySoft, Inc.>
[ElbyCDIO Driver / ElbyCDIO][Running/Auto Start]
  <System32\Drivers\ElbyCDIO.sys><Elaborate Bytes AG>
[ENTECH / ENTECH][Stopped/Manual Start]
  <\??\G:\WINDOWS\System32\DRIVERS\ENTECH.sys><EnTech Taiwan>
[kl1 / kl1][Running/Boot Start]
  <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
  <\??\G:\WINDOWS\System32\drivers\klif.sys><Kaspersky Lab>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <System32\DRIVERS\npf.sys><NetGroup - Politecnico di Torino>
[Upper Class Filter Driver / NTIDrvr][Running/System Start]
  <System32\DRIVERS\NTIDrvr.sys><NewTech Infosystems, Inc.>
[nv / nv][Stopped/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Padus ASPI Shell / pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  <System32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[squell1 / squell1][Stopped/Manual Start]
  <\??\G:\DOCUME~1\Fireli\LOCALS~1\Temp\winrar.sys><N/A>
[SVKP / SVKP][Running/Auto Start]
  <\??\G:\WINDOWS\System32\SVKP.sys><AntiCracking>
[TSP / TSP][Stopped/Manual Start]
  <\??\G:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[WINIO / WINIO][Stopped/Manual Start]
  <\??\I:\DRIVER\AUDIO\winio.sys><N/A>
==================================
浏览器加载项
[MSNToolBandBHO]
  {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-hk\msntb.dll, Microsoft Corporation>
[浩方对战平台]
  {0A155D3C-68E2-4215-A47A-E800A446447A} <D:\software\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[Web反病毒统计]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <G:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[使用影音传送带下载]
  <D:\software\NetTransport 2\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
  <D:\software\NetTransport 2\NTAddList.html, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\software\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\software\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\software\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\software\qq\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
  <D:\software\BitSpirit\bsurl.htm, N/A>
==================================
正在运行的进程
[PID: 1592][G:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl23qso.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl32qso.dll]  [N/A, ]
    [G:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [G:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\software setup\adop\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [G:\Program Files\winrar\rarext.dll]  [N/A, ]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\shellex.dll]  [Kaspersky Lab, 6.0.2.621]
    [G:\WINDOWS\System32\Audiodev.dll]  [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
    [D:\software\MICROSOFT\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 1948][G:\WINDOWS\LOGI_MWX.EXE]  [Logitech Inc., 9.80.013]
    [G:\WINDOWS\System32\dl32qso.dll]  [N/A, ]
    [G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl23qso.dll]  [N/A, ]
[PID: 168][G:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl32qso.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl23qso.dll]  [N/A, ]
[PID: 1380][G:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl32qso.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl23qso.dll]  [N/A, ]
[PID: 496][D:\software\Winamp\winamp.exe]  [Nullsoft, 2.78c]
    [G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl32qso.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl23qso.dll]  [N/A, ]
    [D:\software\Winamp\Plugins\IN_CDDA.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\IN_MIDI.DLL]  [N/A, ]
    [G:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [G:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\software\Winamp\Plugins\READ_FILE.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\IN_MOD.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\IN_MP3.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\IN_WAVE.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\IN_WM.DLL]  [N/A, ]
    [G:\WINDOWS\System32\wmaudsdk.dll]  [Microsoft Corporation, 4.00.0.3845]
    [D:\software\Winamp\Plugins\OUT_DISK.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\OUT_DS.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\OUT_WAVE.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\OUT_WM.DLL]  [N/A, ]
    [D:\software\Winamp\Plugins\DSP_DFX.DLL]  [N/A, ]
    [G:\WINDOWS\System32\dfxg11.dll]  [N/A, ]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]
    [G:\WINDOWS\System32\msaud32.acm]  [Microsoft Corporation, 8.00.00.4487]
    [G:\WINDOWS\System32\imaadp32.acm]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [G:\WINDOWS\System32\msadp32.acm]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [G:\WINDOWS\System32\msg711.acm]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [G:\WINDOWS\System32\msgsm32.acm]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [G:\WINDOWS\System32\tssoft32.acm]  [DSP GROUP, INC., 1.01]
    [G:\WINDOWS\System32\tsd32.dll]  [, ]
    [G:\WINDOWS\System32\msg723.acm]  [Microsoft Corporation, 4.4.3400]
    [G:\WINDOWS\System32\sl_anet.acm]  [Sipro Lab Telecom Inc., 3.02]
    [G:\WINDOWS\System32\L3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 2, 0, 63]
    [G:\WINDOWS\System32\DivXa32.acm]  [Hacked With Joy !, 4.1.00.3920]
    [G:\WINDOWS\System32\sirenacm.dll]  [Microsoft Corp., 7.5.0324.0]
    [G:\WINDOWS\System32\lhacm.acm]  [Microsoft Corporation, 4.4.3385]
    [G:\WINDOWS\System32\vorbis.acm]  [HMS http://hp.vector.co.jp/authors/VA012897/, 0, 0, 3, 6]
[PID: 584][D:\software\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 5, 8, 116]
    [D:\software\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl32qso.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl23qso.dll]  [N/A, ]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\software\Maxthon\Plugin\FloatBar\FloatBar.dll]  [, 1, 8, 0, 0]
    [D:\software\Maxthon\Plugin\uc\uc.dll]  [, 1, 0, 0, 1]
    [G:\WINDOWS\System32\odbcbcp.dll]  [Microsoft Corporation, 2000.081.9030.00]
    [G:\WINDOWS\System32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\perfcounter.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CorperfmonExt.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [D:\software\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [G:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL]  [Microsoft Corporation, 5.10.2925.0]
    [D:\software\flmpc\Codecs\VSFilter.dll]  [Gabest, 1, 0, 1, 3]
    [D:\software\flmpc\Codecs\PmpSplitter.ax]  [cooleyes, 1, 0, 0, 8]
    [D:\software\flmpc\Codecs\RadGtSplitter.ax]  [Gabest, 1, 0, 0, 0]
    [D:\software\flmpc\Codecs\RMSplt.ax]  [Gabest, 1, 0, 1, 1]
    [D:\software\flmpc\Codecs\FLVSPL~1.AX]  [Gabest, 1, 0, 0, 1]
    [D:\software\Adobe Premiere\mcspmpeg.ax]  [MainConcept AG, 1, 0, 0, 51]
    [D:\software\Adobe Premiere\mpegin.dll]  [MainConcept AG, prerelease build]
    [D:\software\Adobe Premiere\mcmpgdec.dll]  [MainConcept AG, official release build]
    [D:\software\Adobe Premiere\msvcr70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [D:\software\flmpc\Codecs\ffdshow.ax]  [, 1.0.2.2225]
    [G:\WINDOWS\System32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [G:\WINDOWS\System32\MMSwitch.ax]  [Morgan Multimedia, 0, 9, 9, 0]
    [G:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [G:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[PID: 1608][D:\software setup\rse\mykill.exe]  [Smallfrogs Studio, 2.4.12.806]
    [G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl32qso.dll]  [N/A, ]
    [G:\WINDOWS\System32\dl23qso.dll]  [N/A, ]
    [G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]
==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["G:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1       localhost
==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBAEA8AF0)
RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBAEA8CD0)
RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBAEA8E30)
RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBAEA8BE0)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xBAEA8DE0)
==================================
隐藏进程
    [1504] G:\WINDOWS\System32\RpcS.exe
    [1516] G:\Program Files\Internet Explorer\IEXPLORE.EXE
==================================

[/CODE]
x361945
 楼主| 发表于 2007-4-17 20:54:11 | 显示全部楼层
下面上hijack的日志

HijackThis_815汉化版扫描日志 V1.99.1
保存于      20:46:05, 日期 2007-4-17
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:         
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\System32\Ati2evxx.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\Ati2evxx.exe
G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\LOGI_MWX.EXE
G:\WINDOWS\System32\ctfmon.exe
G:\WINDOWS\System32\conime.exe
D:\software\Winamp\winamp.exe
D:\software\Maxthon\Maxthon.exe
D:\wei\hijack.exe
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-hk\msntb.dll
O4 - 启动项HKLM\\Run: [Logitech Utility] LOGI_MWX.EXE
O4 - 启动项HKLM\\Run: [TkBellExe] ; "G:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [MSConfig] G:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - 启动项HKLM\\Run: [ATICCC] ; "G:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - 启动项HKLM\\Run: [ATIPTA] ; G:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [CloneCDTray] ;
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] ; "G:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - 启动项HKLM\\Run: [defender] ; C:\\dfndrff_8.exe
O4 - 启动项HKLM\\Run: [exp1orer] ; G:\WINDOWS\System32\exp1orer.exe
O4 - 启动项HKLM\\Run: [fenglei] ; D:\software\flmpc\fengleiLive.exe
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "G:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [keyboard] ; C:\\kybrdff_8.exe
O4 - 启动项HKLM\\Run: [Messager.exe] ; G:\Program Files\Tencent\QQ\Messenger.exe
O4 - 启动项HKLM\\Run: [Messenger.exe] ; G:\Program Files\Tencent\QQ\Messenger.exe
O4 - 启动项HKLM\\Run: [msnappau] ; "G:\Program Files\MSN Apps\Updater\01.02.3000.1001\zh-hk\msnappau.exe"
O4 - 启动项HKLM\\Run: [NeroFilterCheck] ; G:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [newname] ; C:\\nwnmff_8.exe
O4 - 启动项HKLM\\Run: [NvCplDaemon] ; RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] ; nwiz.exe /install
O4 - 启动项HKLM\\Run: [PHIME2002A] ; G:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; G:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [Realplayer.exe] ; G:\Program Files\Tencent\QQ\Messenger.exe
O4 - 启动项HKLM\\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [SunJavaUpdateSched] ; G:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - 启动项HKLM\\Run: [WangWang] ;
O4 - 启动项HKLM\\Run: [WinampAgent] ; "D:\software\Winamp\Winampa.exe"
O4 - 启动项HKLM\\Run: [zcom] ; \zPlatform.exe MIN
O4 - 启动项HKLM\\Run: [_rx] ; G:\WINDOWS\command\rundll32.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] ; "G:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] ;
O4 - HKCU\..\Run: [sys001] ; G:\WINDOWS\rundll32.exe
O4 - HKCU\..\Run: [system] ; c:\SVCHOST.exe
O4 - HKCU\..\Run: [WeatherBug] ; C:\Program Files\AWS\WeatherBug\WeatherBug.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - D:\software\NetTransport 2\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - D:\software\NetTransport 2\NTAddList.html
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\software\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\software\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\software\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\software\qq\SendMMS.htm
O8 - IE右键菜单中的新增项目: 用比特精灵下载(&B) - D:\software\BitSpirit\bsurl.htm
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\software\浩方对战平台\GameClient.exe
O9 - 浏览器额外的按钮: Web反病毒统计 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - G:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - G:\WINDOWS\web\related.htm
O15 - “受信任的站点”中添加项: http://www.ctuonline.com.cn
O17 - HKLM\System\CCS\Services\Tcpip\..\{2ABA6737-9041-4D99-9135-EC704C86B7B4}: NameServer = 202.96.209.6,202.96.209.133
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "G:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Applets - G:\WINDOWS\
O20 - Winlogon Notify: klogon - G:\WINDOWS\System32\klogon.dll
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - G:\WINDOWS\System32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - G:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: 卡巴斯基互联网安全套装6.0个人版 (AVP) - Unknown owner - G:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - NT 服务: PDEngine - Raxco Software, Inc. - G:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - NT 服务: PDScheduler (PDSched) - Raxco Software, Inc. - G:\Program Files\Raxco\PerfectDisk\PDSched.exe
wangjay1980
发表于 2007-4-17 22:26:53 | 显示全部楼层
<1MJPMIG__><; G:\WINDOWS\IMEINPUTS.EXE>  []
    <MSMSGS><; "G:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
    <MsnMsgr><; >  [N/A]
    <sys001><; G:\WINDOWS\rundll32.exe>  [N/A]
    <system><; c:\SVCHOST.exe>  [N/A]
    <WeatherBug><; C:\Program Files\AWS\WeatherBug\WeatherBug.exe>  [(Verified)WeatherBug]
<Logitech Utility><LOGI_MWX.EXE>  [Logitech Inc.]
    <TkBellExe><; "G:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
    <MSConfig><G:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto>  [(Verified)Microsoft Windows XP Publisher]
    <ATICCC><; "G:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe">  [N/A]
    <ATIPTA><; G:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [N/A]
    <CloneCDTray><; >  [N/A]
    <DAEMON Tools-1033><; "G:\Program Files\D-Tools\daemon.exe"  -lang 1033>  [DAEMON'S HOME]
    <defender><; C:\\dfndrff_8.exe>  [N/A]
    <exp1orer><; G:\WINDOWS\System32\exp1orer.exe>  [N/A]
    <fenglei><; D:\software\flmpc\fengleiLive.exe>  [风雷影音工作室]
    <IMJPMIG8.1><; "G:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  [N/A]
    <keyboard><; C:\\kybrdff_8.exe>  [N/A]
    <Messager.exe><; G:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <Messenger.exe><; G:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <msnappau><; "G:\Program Files\MSN Apps\Updater\01.02.3000.1001\zh-hk\msnappau.exe">  [Microsoft Corporation]
    <NeroFilterCheck><; G:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <newname><; C:\\nwnmff_8.exe>  [N/A]
    <NvCplDaemon><; RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <nwiz><; nwiz.exe /install>  [NVIDIA Corporation]
    <PHIME2002A><; G:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
    <PHIME2002ASync><; G:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
    <Realplayer.exe><; G:\Program Files\Tencent\QQ\Messenger.exe>  [N/A]
    <SoundMan><; SOUNDMAN.EXE>  [(Verified)Microsoft Windows XP Publisher]
    <SunJavaUpdateSched><; G:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe>  []
    <WangWang><; >  [N/A]
    <WinampAgent><; "D:\software\Winamp\Winampa.exe">  []
    <zcom><; \zPlatform.exe MIN>  [N/A]
    <_rx><; G:\WINDOWS\command\rundll32.exe>  [N/A]
<AppInit_DLLs><KB235780M.LOG,G:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll>  [N/A]
<{220BF032-F032-20B1-3220-0320B03220B1}><G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll>  []
    <{1B4E3287-2C14-F46E-89D0-AADD240C8576}><G:\WINDOWS\System32\dl23qso.dll>  []
    <{274B93C2-A6DF-485F-8576-AB0653134A76}><G:\WINDOWS\System32\dl32qso.dll>  []
这些启动项删除

[Remote Access Auto Connection Manager / RasAuto][Running/Auto Start]
  <G:\WINDOWS\System32\svchost.exe -k netsvcs-->G:\WINDOWS\System32\rasaute_2.dll><N/A>
[Remote Procedure Call System(RPCS) / RpcS][Running/Auto Start]
  <G:\WINDOWS\System32\RpcS.exe><Microsoft Corporation>
[RtmoteAccess / RtmoteAccess][Stopped/Disabled]
  <G:\WINDOWS\windowse><N/A>
这些服务删除

[squell1 / squell1][Stopped/Manual Start]
  <\??\G:\DOCUME~1\Fireli\LOCALS~1\Temp\winrar.sys><N/A>
[SVKP / SVKP][Running/Auto Start]
  <\??\G:\WINDOWS\System32\SVKP.sys><AntiCracking>
这两个驱动删除

G:\Program Files\Common Files\Microsoft Shared\MSINFO\F03220B1.dll
G:\WINDOWS\System32\dl23qso.dll
G:\WINDOWS\System32\dl32qso.dll
G:\WINDOWS\System32\RpcS.exe
按路径删除

最后用这个清理,清理后修复安装卡巴,进行全盘查杀

arswp.rar

590.29 KB, 下载次数: 36

wangjay1980
发表于 2007-4-17 22:28:15 | 显示全部楼层
最好再用360进行查杀
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 02:23 , Processed in 0.131936 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表