查看: 2683|回复: 11
收起左侧

求助高手解决!!卡巴6.0.1.411无法查杀

[复制链接]
fghj720
发表于 2007-6-2 11:48:40 | 显示全部楼层 |阅读模式
病毒名称:NhYPcmW.com

发作时会自动在用户temp文件夹下面创建NhYPcmW.com和VTuWsFT.vbs文件,然后自动运行NhYPcmW.com
连接到www.s233.com这个网址去下载木马文件,已经是今天最新的病毒库了,求助解决方法!
1.jpg
SRE报告如下:


  1. 2007-06-02,12:20:15
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows 2000 Professional Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件

  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <Internat.exe><internat.exe>  [(Verified)Microsoft Windows 2000 Publisher]
  17. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  18.     <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Windows 2000 Publisher]
  19.     <NvCplDaemon><RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  20.     <nwiz><nwiz.exe /install>  [NVIDIA Corporation]
  21.     <NvMediaCenter><RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  22.     <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  23.     <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  25.     <shell><Explorer.exe>  [(Verified)Microsoft Windows 2000 Publisher]
  26.     <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Windows 2000 Publisher]
  27. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  28.     <WinlogonNotify: klogon><C:\WINNT\System32\klogon.dll>  [Kaspersky Lab]
  29. [HKEY_CURRENT_USER\Control Panel\Desktop]
  30.     <SCRNSAVE.EXE><(无)>  [N/A]
  31. ==================================
  32. 启动文件夹
  33. [Microsoft Office]
  34.   <C:\Documents and Settings\xxzx1\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>
  35. ==================================
  36. 服务
  37. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  38.   <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe -r><Kaspersky Lab>
  39. [Microsoft Update Service / BARCASE][Stopped/Auto Start]
  40.   <><N/A>
  41. [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  42.   <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
  43. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  44.   <C:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
  45. [Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  46.   <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\System32\mspmsnsv.dll><Microsoft Corporation>
  47. ==================================
  48. 驱动程序
  49. [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  50.   <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
  51. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  52.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  53. [dmboot / dmboot][Stopped/Disabled]
  54.   <System32\drivers\dmboot.sys><VERITAS Software Corp.>
  55. [Logical Disk Manager Driver / dmio][Running/Boot Start]
  56.   <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
  57. [dmload / dmload][Running/Boot Start]
  58.   <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
  59. [kl1 / kl1][Running/Boot Start]
  60.   <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
  61. [klif / klif][Running/System Start]
  62.   <\??\C:\WINNT\System32\drivers\klif.sys><Kaspersky Lab>
  63. [npkcrypt / npkcrypt][Running/Auto Start]
  64.   <\??\C:\Program Files\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
  65. [nv / nv][Running/Manual Start]
  66.   <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  67. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  68.   <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  69. [Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  70.   <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  71. [sptd / sptd][Running/Boot Start]
  72.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  73. [4954531 / 4954531][Running/Manual Start]
  74.   <2 - 系统找不到指定的文件。
  75. ><N/A>
  76. ==================================
  77. 浏览器加载项
  78. [ThunderAtOnce Class]
  79.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  80. [Thunder Browser Helper]
  81.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  82. [启动迅雷5]
  83.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
  84. [Web反病]
  85.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  86. [@shdoclc.dll,-866]
  87.   {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
  88. [@msdxmLC.dll,-1@2052,电台(&R)]
  89.   {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
  90. [Windows Genuine Advantage Validation Tool]
  91.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINNT\System32\LegitCheckControl.DLL, Microsoft Corporation>
  92. [Thunder Agent Class]
  93.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  94. [上传到QQ网络硬盘]
  95.   <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
  96. [使用迅雷下载]
  97.   <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
  98. [使用迅雷下载全部链接]
  99.   <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
  100. [添加到QQ自定义面板]
  101.   <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
  102. [添加到QQ表情]
  103.   <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
  104. [用QQ彩信发送该图片]
  105.   <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
  106. ==================================
  107. 正在运行的进程
  108. [PID: 232][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  109. [PID: 256][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  110. [PID: 252][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6714]
  111.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  112.     [C:\WINNT\System32\klogon.dll]  [Kaspersky Lab, 6.0.1.411]
  113.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  114. [PID: 304][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.6700]
  115.     [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
  116. [PID: 1080][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
  117.     [C:\WINNT\AppPatch\AcLayers.DLL]  [Microsoft Corporation, 5.00.2195.6717]
  118.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 1.0.6.411]
  119.     [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8168.0]
  120.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  121.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  122.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.1.411]
  123.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll]  [Kaspersky Lab, 6.0.1.411]
  124.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.1.411]
  125.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.1.411]
  126.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.1.411]
  127.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.1.411]
  128.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.1.411]
  129.     [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
  130.     [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
  131.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 2]
  132.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
  133.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  134.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\ShellEx.dll]  [Kaspersky Lab, 6.0.1.411]
  135. [PID: 1236][C:\WINNT\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.00.2134.1]
  136.     [C:\WINNT\System32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.10.5664]
  137. [PID: 1244][C:\WINNT\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.24]
  138. [PID: 1264][C:\WINNT\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
  139. [PID: 1440][C:\WINNT\system32\conime.exe]  [Microsoft Corporation, 5.00.2195.6655]
  140. [PID: 1008][C:\WINNT\system32\taskmgr.exe]  [Microsoft Corporation, 5.00.2195.6620]
  141. [PID: 1408][C:\Program Files\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 5, 9, 30]
  142.     [C:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
  143.     [C:\Program Files\Maxthon\Plugin\FloatBar\FloatBar.dll]  [, 1, 8, 0, 0]
  144.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 1.0.6.411]
  145.     [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8168.0]
  146.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.1.411]
  147.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll]  [Kaspersky Lab, 6.0.1.411]
  148.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.1.411]
  149.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.1.411]
  150.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.1.411]
  151.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.1.411]
  152.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.1.411]
  153.     [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
  154.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  155.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.1.411]
  156.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  157.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.1.411]
  158.     [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
  159.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\basegui.ppl]  [Crsky, 6.0.1]
  160.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\winreg.ppl]  [Kaspersky Lab, 6.0.1.411]
  161.     [C:\WINNT\System32\msxml3.dll]  [Microsoft Corporation, 8.30.9926.0]
  162.     [C:\WINNT\system32\PINTLGNT.IME]  [Microsoft Corporation, 4.2.32]
  163.     [C:\WINNT\system32\MSDART.DLL]  [Microsoft Corporation, 2.71.9030.0 built by: Lab06_N(dagbuild)]
  164.     [C:\WINNT\system32\msratelc.dll]  [Microsoft Corporation, 6.00.2800.1106]
  165. [PID: 980][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5, 6, 2, 300]
  166.     [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8168.0]
  167.     [C:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 1, 0, 21]
  168.     [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 85]
  169.     [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
  170.     [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 85]
  171.     [C:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
  172.     [C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DownAndPlay.dll]  [, 1, 0, 0, 3]
  173.     [C:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 26]
  174.     [C:\WINNT\System32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
  175.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  176.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  177.     [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 17]
  178.     [C:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 1, 0, 8, 30]
  179.     [C:\Program Files\Thunder Network\Thunder\Components\Security\ThunderSafe.dll]  [深圳市迅雷网络技术有限公司, 1.0.0.10]
  180.     [C:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 12]
  181.     [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 46]
  182.     [C:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll]  [Thunder Networking Technologies,LTD, 1, 2, 1, 20]
  183.     [C:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
  184.     [C:\Program Files\Thunder Network\Thunder\Components\Tips\TipsClient.dll]  [Thunder Networking Technologies,LTD, 2, 1, 3, 58]
  185.     [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll]  [XunLei, 1, 2, 0, 10]
  186.     [C:\Program Files\Thunder Network\Thunder\Components\UserExperience\UserExperience.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
  187.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsXlCom.dll]  [, 1, 0, 0, 9]
  188.     [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed09.dll]  [ , 3, 3, 0, 80]
  189.     [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 13, 2, 61]
  190.     [C:\Program Files\Thunder Network\Thunder\Program\XLNet.Dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
  191.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 1.0.6.411]
  192.     [C:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll]  [深圳市迅雷网络技术有限公司, 1.0.1.0]
  193.     [C:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll]  [XunLei, 1, 2, 0, 11]
  194.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
  195.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\MediaWorker.dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
  196.     [C:\WINNT\system32\WMVCore.DLL]  [Microsoft Corporation, 9.00.00.2980 built by: lab03_dev(bld4act)]
  197.     [C:\WINNT\system32\WMASF.DLL]  [Microsoft Corporation, 9.00.00.2980 built by: lab03_dev(bld4act)]
  198.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.1.411]
  199.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll]  [Kaspersky Lab, 6.0.1.411]
  200.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.1.411]
  201.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.1.411]
  202.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.1.411]
  203.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.1.411]
  204.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.1.411]
  205.     [C:\WINNT\system32\MSDART.DLL]  [Microsoft Corporation, 2.71.9030.0 built by: Lab06_N(dagbuild)]
  206.     [C:\WINNT\System32\msxml3.dll]  [Microsoft Corporation, 8.30.9926.0]
  207.     [C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  [Giganology Inc., 1, 0, 0, 2]
  208.     [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
  209. [PID: 1656][F:\卡巴斯基\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  210. ==================================
  211. 文件关联
  212. .TXT  Error. [C:\WINNT\notepad.exe %1]
  213. .EXE  OK. ["%1" %*]
  214. .COM  OK. ["%1" %*]
  215. .PIF  OK. ["%1" %*]
  216. .REG  OK. [regedit.exe "%1"]
  217. .BAT  OK. ["%1" %*]
  218. .SCR  OK. ["%1" /S]
  219. .CHM  Error. ["hh.exe" %1]
  220. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  221. .INI  Error. [C:\WINNT\System32\NOTEPAD.EXE %1]
  222. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  223. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  224. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  225. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  226. ==================================
  227. Winsock 提供者
  228. N/A
  229. ==================================
  230. Autorun.inf
  231. N/A
  232. ==================================
  233. HOSTS 文件
  234. N/A
  235. ==================================
  236. API HOOK
  237. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBE8B7B25)
  238. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBE8B7D67)
  239. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBE8B7F0B)
  240. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xBE8B7C49)
  241. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xBE8B7E8F)
  242. ==================================
  243. 隐藏进程
  244. N/A
  245. ==================================
复制代码

[ 本帖最后由 fghj720 于 2007-6-2 12:26 编辑 ]
beyond145
发表于 2007-6-2 11:51:55 | 显示全部楼层
你更新了再杀下44  

[ 本帖最后由 beyond145 于 2007-6-2 11:53 编辑 ]
mds
发表于 2007-6-2 11:52:23 | 显示全部楼层
temp文件目录下的文件可以删除的!都是临时文件!
无法查杀是什么意思?病毒删除不掉?
你的图看不到
用这个地址登录后在修改图!
http://bbs.kafan.cn/index.php
nealee
发表于 2007-6-2 11:53:47 | 显示全部楼层
看不到图片,LZ 重新编辑一下吧。。
fghj720
 楼主| 发表于 2007-6-2 11:56:03 | 显示全部楼层
手动杀出那两个文件后,过一段时间会自动创建
xffsfy
发表于 2007-6-2 12:12:22 | 显示全部楼层
用SRE扫报告
mds
发表于 2007-6-2 12:44:48 | 显示全部楼层
<SCRNSAVE.EXE><(无)>  [N/A]
是“密蜂大盗"木马删除它!

<2 - 系统找不到指定的文件。
><N/A>
删除!

修复错误文件关联!

[ 本帖最后由 mds 于 2007-6-2 13:12 编辑 ]
fghj720
 楼主| 发表于 2007-6-2 13:27:15 | 显示全部楼层
已经将SCRNSAVE.EXE删除了,可问题依旧
mds
发表于 2007-6-2 13:32:23 | 显示全部楼层

回复 #8 fghj720 的帖子

卸载411安装621!
robertfaye
发表于 2007-6-2 13:34:04 | 显示全部楼层
不一定非要用KAV杀,找得到就行.用ICESWORD手动杀试试
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 11:37 , Processed in 0.166950 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表