查看: 2236|回复: 9
收起左侧

卡8杀不死的病毒请大家帮忙看看!

[复制链接]
w0430y
发表于 2007-5-21 22:08:56 | 显示全部楼层 |阅读模式
我每次启动机子都有这样一个病毒  Packed.Win32.PePatch.cp  运行模块: Mpservice\Mpservice  卡把杀不死,请问怎么解决!
wangjay1980
发表于 2007-5-21 22:09:32 | 显示全部楼层
扫个报告上来
w0430y
 楼主| 发表于 2007-5-21 22:24:15 | 显示全部楼层
截的个图,每次开机都扫得出来
{C2676A5C-433F-46D2-B7BB-B0C3B62A743F}0.jpg
wangjay1980
发表于 2007-5-21 22:40:30 | 显示全部楼层
用SRE扫个系统诊断报告
w0430y
 楼主| 发表于 2007-5-22 20:14:20 | 显示全部楼层


  1. 2007-05-22,19:48:23

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17.     <P2kAutostart><>  [N/A]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.     <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  20.     <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
  21.     <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [NVIDIA Corporation]
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  23.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  24.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  25.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]

  26. ==================================
  27. 启动文件夹
  28. [Kaspersky Anti-Hacker]
  29.   <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Kaspersky Anti-Hacker.lnk --> C:\PROGRA~1\KASPER~1\KASPER~1\KAVPF.exe [Kaspersky Lab]><N>

  30. ==================================
  31. 服务
  32. [Alertera / Alertera][Stopped/Auto Start]
  33.   <C:\WINDOWS\Alertera.exe><N/A>
  34. [Application Layer Gateway Serv / Application Layer Gateway Serv][Stopped/Auto Start]
  35.   <><N/A>
  36. [AutoComplete Service / Autocomplete][Stopped/Manual Start]
  37.   <d:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe><Acesoft>
  38. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  39.   <C:\Program Files\avgas\avgas\guard.exe><Anti-Malware Development a.s.>
  40. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  41.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  42. [Gray_Pigeon_Server1.2 / GrayPigeonServer1.2][Stopped/Auto Start]
  43.   <><N/A>
  44. [Human Interface Device Access / HidServ][Stopped/Disabled]
  45.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  46. [iPod 服务 / iPod Service][Stopped/Manual Start]
  47.   <"C:\Program Files\iPod\bin\iPodService.exe"><Apple Inc.>
  48. [Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
  49.   <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
  50. [Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
  51.   <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>

  52. ==================================
  53. 驱动程序
  54. [Service for Avance AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  55.   <system32\drivers\ALCXWDM.SYS><Avance Logic, Inc.>
  56. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  57.   <\??\C:\Program Files\avgas\avgas\guard.sys><N/A>
  58. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  59.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  60. [Cdsys / Cdsys][Stopped/Manual Start]
  61.   <\??\C:\WINDOWS\system32\cdcd.sys><N/A>
  62. [GEARAspiWDM / GEARAspiWDM][Stopped/Manual Start]
  63.   <System32\Drivers\GEARAspiWDM.sys><GEAR Software Inc.>
  64. [kl1 / kl1][Running/Boot Start]
  65.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  66. [KLIF / KLIF][Running/System Start]
  67.   <System32\drivers\klif.sys><Kaspersky Lab>
  68. [Klpf / Klpf][Running/Boot Start]
  69.   <\SystemRoot\System32\drivers\Klpf.sys><KL>
  70. [Klpid / Klpid][Running/Boot Start]
  71.   <\SystemRoot\System32\drivers\Klpid.sys><KL>
  72. [Digital Audio Player Driver / Mp3Drv][Stopped/Manual Start]
  73.   <System32\Drivers\Mp3Drv.sys><TGE, Ltd.>
  74. [npkcrypt / npkcrypt][Running/Auto Start]
  75.   <\??\d:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  76. [nv / nv][Running/Manual Start]
  77.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  78. [Motorola USB Device / P2k][Stopped/Manual Start]
  79.   <system32\DRIVERS\P2k.sys><Motorola Inc>
  80. [Padus ASPI Shell / pfc][Stopped/Manual Start]
  81.   <system32\drivers\pfc.sys><Padus, Inc.>
  82. [PNP28349 / PNP28349][Running/Boot Start]
  83.   <\SystemRoot\system32\Drivers\pnp28317.sys><Anti Driver>
  84. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  85.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  86. [PxHelp20 / PxHelp20][Running/Boot Start]
  87.   <\SystemRoot\system32\DRIVERS\PxHelp20.sys><Sonic Solutions>
  88. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  89.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  90. [Secdrv / Secdrv][Stopped/Manual Start]
  91.   <system32\DRIVERS\secdrv.sys><N/A>
  92. [MS3303H2 Serial port driver / Ser2pl][Stopped/Manual Start]
  93.   <system32\DRIVERS\ser2pl.sys><MS3303H>
  94. [sptd / sptd][Running/Boot Start]
  95.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  96. [StScsi / StScsi][Stopped/Manual Start]
  97.   <system32\DRIVERS\StScsi.sys><TGE, Ltd.>
  98. [TSP / TSP][Stopped/Manual Start]
  99.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  100. [vaxscsi / vaxscsi][Stopped/Manual Start]
  101.   <\SystemRoot\System32\Drivers\vaxscsi.sys><Alcohol Soft Co., Ltd.>
  102. [ViaIde / ViaIde][Running/Boot Start]
  103.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  104. [Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
  105.   <system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
  106. [Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
  107.   <system32\DRIVERS\wudfrd.sys><Microsoft Corporation>
  108. [zmwaptge / zmwaptge][Running/Boot Start]
  109.   <\SystemRoot\System32\DRIVERS\zmwaptge.sys><Yahoo! China Corporation>

  110. ==================================
  111. 浏览器加载项
  112. [IeCatch5 Class]
  113.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <d:\Program Files\FlashGet\Jccatch.dll, FlashGet>
  114. [FlashGet Bar]
  115.   {E0E899AB-F487-11D5-8D29-0050BA6940E3} <d:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
  116. [金山快译(&K)]
  117.   {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
  118. [PasswordEditCtrl Class]
  119.   {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
  120. [Windows Media Player]
  121.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  122. [IeCatch5 Class]
  123.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <d:\Program Files\FlashGet\Jccatch.dll, FlashGet>
  124. [金山快译(&K)]
  125.   {6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
  126. [Shockwave Flash Object]
  127.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  128. [FlashGet Bar]
  129.   {E0E899AB-F487-11D5-8D29-0050BA6940E3} <d:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
  130. [上传到QQ网络硬盘]
  131.   <, N/A>
  132. [使用网际快车下载]
  133.   <D:\Program Files\FlashGet\jc_link.htm, N/A>
  134. [使用网际快车下载全部链接]
  135.   <D:\Program Files\FlashGet\jc_all.htm, N/A>
  136. [添加到QQ自定义面板]
  137.   <, N/A>
  138. [添加到QQ表情]
  139.   <, N/A>
  140. [用QQ彩信发送该图片]
  141.   <, N/A>

  142. ==================================
  143. 正在运行的进程
  144. [PID: 552][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  145. [PID: 612][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  146. [PID: 636][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  147.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  148. [PID: 680][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  149. [PID: 692][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  150. [PID: 848][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  151. [PID: 924][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  152. [PID: 968][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  153. [PID: 1432][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  154.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  155.     [d:\Program Files\FlashGet\Jccatch.dll]  [FlashGet, 1, 1, 5, 0]
  156.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  157.     [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9371]
  158.     [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9371]
  159.     [C:\WINDOWS\system32\nvapi.dll]  [N/A, ]
  160.     [C:\WINDOWS\system32\nvshell.dll]  [, ]
  161. [PID: 1836][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3510]
  162. [PID: 1872][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  163. [PID: 1964][C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe]  [Kaspersky Lab, 1.9.0.37]
  164.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\BCGCB59.dll]  [BCGSoft Ltd, 5, 84, 0, 0]
  165.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\perfiloc.dll]  [Kaspersky 实验室, 1.5.0.0]
  166.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\wcswmi.dll]  [Kaspersky Lab, 5.0.201.1]
  167. [PID: 768][D:\工具\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]

  168. ==================================
  169. 文件关联
  170. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  171. .EXE  OK. ["%1" %*]
  172. .COM  OK. ["%1" %*]
  173. .PIF  OK. ["%1" %*]
  174. .REG  OK. [regedit.exe "%1"]
  175. .BAT  OK. ["%1" %*]
  176. .SCR  OK. ["%1" /S]
  177. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  178. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  179. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  180. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  181. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  182. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  183. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  184. ==================================
  185. Winsock 提供者
  186. N/A

  187. ==================================
  188. Autorun.inf
  189. N/A

  190. ==================================
  191. HOSTS 文件
  192. N/A

  193. ==================================
  194. API HOOK
  195. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4B25)
  196. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4D67)
  197. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4F0B)
  198. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4C49)
  199. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF69F4E8F)

  200. ==================================
  201. 隐藏进程
  202. N/A

  203. ==================================


复制代码


麻烦个位大大帮小弟看看,被这个病毒郁闷惨了,安全模式下面扫不出来,正常进入系统就有了
wangjay1980
发表于 2007-5-22 21:11:33 | 显示全部楼层
[Alertera / Alertera][Stopped/Auto Start]
  <C:\WINDOWS\Alertera.exe><N/A>
[Application Layer Gateway Serv / Application Layer Gateway Serv][Stopped/Auto Start]
  <><N/A>
[Gray_Pigeon_Server1.2 / GrayPigeonServer1.2][Stopped/Auto Start]
  <><N/A>
这些服务删除

[Cdsys / Cdsys][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\cdcd.sys><N/A>
[PNP28349 / PNP28349][Running/Boot Start]
  <\SystemRoot\system32\Drivers\pnp28317.sys><Anti Driver>
[zmwaptge / zmwaptge][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\zmwaptge.sys><Yahoo! China Corporation>
这些驱动删除
w0430y
 楼主| 发表于 2007-5-22 22:48:15 | 显示全部楼层
wangjay1980 大大
我已经按照你说的做了,但开机还是扫出这个病毒,我要被搞崩溃了,麻烦大大再帮帮忙!看看怎么处理
w0430y
 楼主| 发表于 2007-5-22 22:51:52 | 显示全部楼层
这是删除你喊我删除后的扫描报告


  1. 2007-05-22,22:48:35

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  18.     <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  19.     <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
  20.     <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [NVIDIA Corporation]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  22.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  23.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  24.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]

  25. ==================================
  26. 启动文件夹
  27. [Kaspersky Anti-Hacker]
  28.   <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Kaspersky Anti-Hacker.lnk --> C:\PROGRA~1\KASPER~1\KASPER~1\KAVPF.exe [Kaspersky Lab]><N>

  29. ==================================
  30. 服务
  31. [AutoComplete Service / Autocomplete][Stopped/Manual Start]
  32.   <d:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe><Acesoft>
  33. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  34.   <C:\Program Files\avgas\avgas\guard.exe><Anti-Malware Development a.s.>
  35. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  36.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  37. [Human Interface Device Access / HidServ][Stopped/Disabled]
  38.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  39. [iPod 服务 / iPod Service][Stopped/Manual Start]
  40.   <"C:\Program Files\iPod\bin\iPodService.exe"><Apple Inc.>
  41. [Mpservice / Media Player of Remote Control][Stopped/Auto Start]
  42.   <C:\WINDOWS\system\Mpservice><N/A>
  43. [Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
  44.   <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
  45. [Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
  46.   <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>

  47. ==================================
  48. 驱动程序
  49. [Service for Avance AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  50.   <system32\drivers\ALCXWDM.SYS><Avance Logic, Inc.>
  51. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  52.   <\??\C:\Program Files\avgas\avgas\guard.sys><N/A>
  53. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  54.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  55. [GEARAspiWDM / GEARAspiWDM][Stopped/Manual Start]
  56.   <System32\Drivers\GEARAspiWDM.sys><GEAR Software Inc.>
  57. [kl1 / kl1][Running/Boot Start]
  58.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  59. [KLIF / KLIF][Running/System Start]
  60.   <System32\drivers\klif.sys><Kaspersky Lab>
  61. [Klpf / Klpf][Running/Boot Start]
  62.   <\SystemRoot\System32\drivers\Klpf.sys><KL>
  63. [Klpid / Klpid][Running/Boot Start]
  64.   <\SystemRoot\System32\drivers\Klpid.sys><KL>
  65. [Digital Audio Player Driver / Mp3Drv][Stopped/Manual Start]
  66.   <System32\Drivers\Mp3Drv.sys><TGE, Ltd.>
  67. [npkcrypt / npkcrypt][Running/Auto Start]
  68.   <\??\d:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  69. [nv / nv][Running/Manual Start]
  70.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  71. [Motorola USB Device / P2k][Stopped/Manual Start]
  72.   <system32\DRIVERS\P2k.sys><Motorola Inc>
  73. [Padus ASPI Shell / pfc][Stopped/Manual Start]
  74.   <system32\drivers\pfc.sys><Padus, Inc.>
  75. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  76.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  77. [PxHelp20 / PxHelp20][Running/Boot Start]
  78.   <\SystemRoot\system32\DRIVERS\PxHelp20.sys><Sonic Solutions>
  79. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  80.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  81. [Secdrv / Secdrv][Stopped/Manual Start]
  82.   <system32\DRIVERS\secdrv.sys><N/A>
  83. [MS3303H2 Serial port driver / Ser2pl][Stopped/Manual Start]
  84.   <system32\DRIVERS\ser2pl.sys><MS3303H>
  85. [sptd / sptd][Running/Boot Start]
  86.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  87. [StScsi / StScsi][Stopped/Manual Start]
  88.   <system32\DRIVERS\StScsi.sys><TGE, Ltd.>
  89. [TSP / TSP][Stopped/Manual Start]
  90.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  91. [vaxscsi / vaxscsi][Stopped/Manual Start]
  92.   <\SystemRoot\System32\Drivers\vaxscsi.sys><Alcohol Soft Co., Ltd.>
  93. [ViaIde / ViaIde][Running/Boot Start]
  94.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  95. [Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
  96.   <system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
  97. [Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
  98.   <system32\DRIVERS\wudfrd.sys><Microsoft Corporation>

  99. ==================================
  100. 浏览器加载项
  101. [IeCatch5 Class]
  102.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <d:\Program Files\FlashGet\Jccatch.dll, FlashGet>
  103. [FlashGet Bar]
  104.   {E0E899AB-F487-11D5-8D29-0050BA6940E3} <d:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
  105. [金山快译(&K)]
  106.   {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
  107. [PasswordEditCtrl Class]
  108.   {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <d:\Program Files\Tencent\QQ\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
  109. [Windows Media Player]
  110.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  111. [IeCatch5 Class]
  112.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <d:\Program Files\FlashGet\Jccatch.dll, FlashGet>
  113. [金山快译(&K)]
  114.   {6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
  115. [SearchAssistantOC]
  116.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  117. [RDS.DataSpace]
  118.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  119. [Shockwave Flash Object]
  120.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  121. [FlashGet Bar]
  122.   {E0E899AB-F487-11D5-8D29-0050BA6940E3} <d:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
  123. [上传到QQ网络硬盘]
  124.   <, N/A>
  125. [使用网际快车下载]
  126.   <D:\Program Files\FlashGet\jc_link.htm, N/A>
  127. [使用网际快车下载全部链接]
  128.   <D:\Program Files\FlashGet\jc_all.htm, N/A>
  129. [添加到QQ自定义面板]
  130.   <, N/A>
  131. [添加到QQ表情]
  132.   <, N/A>
  133. [用QQ彩信发送该图片]
  134.   <, N/A>

  135. ==================================
  136. 正在运行的进程
  137. [PID: 552][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  138. [PID: 612][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  139. [PID: 636][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  140.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  141. [PID: 680][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  142. [PID: 692][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  143. [PID: 840][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  144. [PID: 1456][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  145.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  146.     [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9371]
  147.     [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9371]
  148.     [C:\WINDOWS\system32\nvapi.dll]  [N/A, ]
  149.     [C:\WINDOWS\system32\nvshell.dll]  [, ]
  150.     [d:\Program Files\FlashGet\Jccatch.dll]  [FlashGet, 1, 1, 5, 0]
  151.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
  152. [PID: 1968][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  153. [PID: 2000][C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe]  [Kaspersky Lab, 1.9.0.37]
  154.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\BCGCB59.dll]  [BCGSoft Ltd, 5, 84, 0, 0]
  155.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\perfiloc.dll]  [Kaspersky 实验室, 1.5.0.0]
  156.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\wcswmi.dll]  [Kaspersky Lab, 5.0.201.1]
  157. [PID: 3108][D:\工具\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]

  158. ==================================
  159. 文件关联
  160. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  161. .EXE  OK. ["%1" %*]
  162. .COM  OK. ["%1" %*]
  163. .PIF  OK. ["%1" %*]
  164. .REG  OK. [regedit.exe "%1"]
  165. .BAT  OK. ["%1" %*]
  166. .SCR  OK. ["%1" /S]
  167. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  168. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  169. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  170. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  171. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  172. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  173. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  174. ==================================
  175. Winsock 提供者
  176. N/A

  177. ==================================
  178. Autorun.inf
  179. N/A

  180. ==================================
  181. HOSTS 文件
  182. N/A

  183. ==================================
  184. API HOOK
  185. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4B25)
  186. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4D67)
  187. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4F0B)
  188. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69F4C49)
  189. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF69F4E8F)

  190. ==================================
  191. 隐藏进程
  192. N/A

  193. ==================================


复制代码
wangjay1980
发表于 2007-5-22 23:38:11 | 显示全部楼层
[Mpservice / Media Player of Remote Control][Stopped/Auto Start]
  <C:\WINDOWS\system\Mpservice><N/A>
删除这个,应该已经没有问题了
w0430y
 楼主| 发表于 2007-5-23 20:25:44 | 显示全部楼层
谢谢 wangjay1980大大,问题已经得到解决了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 12:32 , Processed in 0.149643 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表