劳驾各位了
病毒吧
全部回复
仅看楼主
level 1
2006-05-18,18:25:23System Repair Engineer 2.0.12.350 (2.0 RC 1) Windows XP Professional Service Pack 1 - 管理权限用户 - 完整功能以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联启动项目注册表[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<>[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<>[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<>==================================启动文件夹[BitComet]
==================================服务[Adobe LM Service / Adobe LM Service] <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe">
[Autodesk Licensing Service / Autodesk Licensing Service] <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe">
[ewido security suite guard / ewido security suite guard]
[InstallDriver Table Manager / IDriverT]
[kavsvc / kavsvc] <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe">
[Kingsoft Personal Firewall Service / KPfwSvc] <"D:\KAV2006\KPfwSvc.EXE">
[Macromedia Licensing Service / Macromedia Licensing Service] <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe">
[Mupssserd / Mupssserd] <>
==================================浏览器加载项[BandIE Class] {77FEF28E-EB96-44FF-B511-3185DEA48697}
[百度超级搜霸] {B580CF65-E151-49C3-B73F-70B13FCA8E86}
[电台(&R)] {8E718888-423F-11D2-876E-00A0C9082467}
[Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000}
[&使用迅雷下载]
[&使用迅雷下载全部链接]
[使用网际快车下载] <, N/A>==================================正在运行的进程[PID: 540][\SystemRoot\System32\smss.exe]
<5.1.2600.1106 (xpsp1.020828-1920)>[PID: 592][\??\C:\WINDOWS\system32\csrss.exe]
<5.1.2600.0 (xpclient.010817-1148)>[PID: 616][\??\C:\WINDOWS\system32\winlogon.exe]
<5.1.2600.1106 (xpsp1.020828-1920)>
2006年05月18日 10点05分 1
level 1
[PID: 660][C:\WINDOWS\system32\services.exe]
<5.1.2600.0 (xpclient.010817-1148)>[PID: 672][C:\WINDOWS\system32\lsass.exe]
<5.1.2600.1106 (xpsp1.020828-1920)>[PID: 836][C:\WINDOWS\system32\svchost.exe]
<5.1.2600.0 (xpclient.010817-1148)>[PID: 872][C:\WINDOWS\System32\svchost.exe]
<5.1.2600.0 (xpclient.010817-1148)>[PID: 944][C:\WINDOWS\System32\svchost.exe]
<5.1.2600.0 (xpclient.010817-1148)>[PID: 956][C:\WINDOWS\System32\svchost.exe]
<5.1.2600.0 (xpclient.010817-1148)>[PID: 1060][C:\WINDOWS\system32\spoolsv.exe]
<5.1.2600.0 (XPClient.010817-1148)>[PID: 1244][C:\WINDOWS\System32\alg.exe]
<5.1.2600.1106 (xpsp1.020828-1920)>[PID: 1304][C:\Program Files\ewido anti-malware\ewidoguard.exe]
<3, 0, 0, 1> [C:\Program Files\ewido anti-malware\framework.dll]
<1, 0, 0, 249> [C:\Program Files\ewido anti-malware\lang.dll]
<1, 0, 0, 1> [C:\Program Files\ewido anti-malware\configuration.dll]
<1, 0, 0, 1> [C:\Program Files\ewido anti-malware\update_core.dll]
[C:\Program Files\ewido anti-malware\wizard.dll]
[C:\Program Files\ewido anti-malware\engine.dll]
<4, 0, 0, 2> [C:\Program Files\ewido anti-malware\scan.dll]
<1, 0, 0, 2> [C:\Program Files\ewido anti-malware\tray_dll.dll]
[PID: 1880][C:\WINDOWS\Explorer.EXE]
<6.00.2800.1106 (xpsp1.020828-1920)> [C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll]
<2, 0, 4, 3> [D:\Program Files\WinRAR\rarext.dll]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll]
<5.0.388.1> [C:\Program Files\ewido anti-malware\context.dll]
<1.0.0.1> [C:\Program Files\ewido anti-malware\lang.dll]
<1, 0, 0, 1> [C:\WINDOWS\System32\CBShell.dll]
<1.0.0.1> [C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll]
[C:\Program Files\Media Player Classic\Codecs\mkunicode.dll]
[C:\WINDOWS\System32\l3codeca.acm]
<1, 9, 0, 0305> [C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll]
<2, 0, 0, 8> [c:\program files\space international\cdspace 5\lcdshell.dll]
<5, 0, 0, 1> [c:\program files\space international\cdspace 5\ScsiControl.dll]
<1, 1, 0, 2> [c:\program files\space international\cdspace 5\ConfigMg.dll]
<1, 0, 0, 2> [C:\Program Files\ewido anti-malware\shellhook.dll]
[C:\WINDOWS\System32\igfxpph.dll]
<3.0.0.3751> [C:\WINDOWS\System32\hccutils.DLL]
<3.0.0.3751>[PID: 2008][C:\WINDOWS\System32\ctfmon.exe]
<5.1.2600.1106 (xpsp1.020828-1920)>
2006年05月18日 10点05分 2
level 1
[PID: 328][C:\WINDOWS\System32\mdm.exe]
<6.00.8149>[PID: 1136][D:\Program Files\eMule\emule.exe]
<0.47.0 Unicode> [D:\Program Files\eMule\lang\zh_CN.dll]
<0.47.0> [C:\Program Files\ewido anti-malware\shellhook.dll]
[PID: 772][C:\Program Files\Thunder Network\Thunder\Thunder.exe]
<5.1.5.189> [C:\Program Files\Thunder Network\Thunder\UpdateDownload.dll]
<1, 0, 0, 2> [C:\Program Files\Thunder Network\Thunder\download_interface.dll]
<1, 0, 2, 74> [C:\Program Files\Thunder Network\Thunder\log4cplus.dll] <><1, 0, 2, 1> [C:\Program Files\Thunder Network\Thunder\stlport_vc646.dll]
<4.6.2003.1031> [C:\Program Files\Thunder Network\Thunder\msgmanage.dll]
<1, 0, 0, 15> [C:\Program Files\Thunder Network\Thunder\historyinfo_manage.dll]
<5, 2, 0, 148> [C:\Program Files\Thunder Network\Thunder\iEmbed.dll]
<1, 1, 0, 22> [C:\Program Files\Thunder Network\Thunder\RegisterDll.dll]
<1, 2, 0, 7> [C:\Program Files\Thunder Network\Thunder\FloatBar.dll]
<1, 0, 0, 2> [C:\Program Files\Thunder Network\Thunder\iTargetAd.dll]
<1, 0, 0, 59> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrchpg.dll]
<5.0.1.18> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrch_ag.dll]
<5.0.388.1> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]
<5.0.388.0> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\pr_rmt.dll]
<5.0.388.0> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ccclient.dll]
<5.0.388.1> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\klipc.dll]
<5.0.388.0> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\KLUtil.dll]
<5.0.388.1> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\rpt.dll]
<5.0.388.2> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\CCIFACE.dll]
<5.0.388.1> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\prloader.dll]
<5.0.388.0> [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\prkernel.ppl]
<5.0.388.0> [c:\program files\kaspersky lab\kaspersky anti-virus personal\prstring.ppl]
<5.0.388.0> [c:\program files\kaspersky lab\kaspersky anti-virus personal\pr_srv.ppl]
<5.0.388.0> [c:\program files\kaspersky lab\kaspersky anti-virus personal\pr_clnt.ppl]
<5.0.388.0> [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]
<8,0,24,0> [C:\Program Files\ewido anti-malware\shellhook.dll]
[PID: 3308][C:\Program Files\金山词霸 2005\xdict.exe]
<8, 5, 0, 0> [C:\Program Files\金山词霸 2005\DicMngr.dll]
<1, 0, 0, 0> [C:\Program Files\金山词霸 2005\doshow.dll]
[C:\Program Files\金山词霸 2005\ITextOut.dll]
<1, 1, 0, 0> [C:\Program Files\金山词霸 2005\KPic10.dll]
[C:\Program Files\金山词霸 2005\ijl11.dll]
<1.1.2> [C:\Program Files\金山词霸 2005\NormGrab.DLL]
<6, 0, 0, 0> [C:\Program Files\金山词霸 2005\toTTSEngine50.dll]
<1, 0, 0, 1> [C:\Program Files\金山词霸 2005\xfile.dll]
[C:\Program Files\金山词霸 2005\DBCore10.dll]
<1, 0, 0, 0> [C:\Program Files\金山词霸 2005\XdictGrb.dll]
<8, 5, 0, 0> [C:\WINDOWS\System32\PNEN3230.DLL]
<3.0.0.76> [C:\WINDOWS\System32\pncrt.dll]
<6.0.0.0>[PID: 784][C:\Documents and Settings\zxc\桌面\sreng2\SREng.exe]
<2.0.12.350>==================================文件关联.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1].EXE OK. ["%1" %*].COM OK. ["%1" %*].PIF OK. ["%1" %*].REG OK. [regedit.exe "%1"].BAT OK. ["%1" %*].SCR OK. ["%1" /S].CHM OK. ["C:\WINDOWS\hh.exe" %1].HLP OK. [%SystemRoot%\system32\winhlp32.exe %1].INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1].INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1].VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*].JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*].LNK OK. [{00021401-0000-0000-C000-000000000046}]==================================Winsock 提供者==================================
2006年05月18日 10点05分 3
1