发新话题
打印

[分享] 这难道是 AVKILLER的变种吗?

这难道是 AVKILLER的变种吗?

刚用 AVKILLER 3.7清楚完后 2天 今天早上开机突然出现 什么 应用程序0X000什么的启动文件不能启动,杀毒软件就不能运行了,怀疑又中了 AVkiller 立刻杀 发现 是0个病毒...而且前几天一只出先 和上位发贴者一样的 .dll文件或者cy..什么的文件一直中毒,但删除不了...请各位大侠 帮帮小弟了!!!

TOP

说清楚现象,或者截个图上来。
推荐最好用的毒霸删除工具,删除病毒、备份样本,一次完成,请将备份病毒的文件夹“_BackUp_”打包上传到样本上传区

请新会员关注新手杀毒入门
提问贴注意详细描述现象、操作过程,如果是病毒报告,应说明病毒名,染毒文件路径、文件名等,请注意不要只发一个LOG,发贴太简单将不能得到正确的答案。

TOP

我的情况差不多,也是和AV一样的反映,就是专杀没办法用,那个什么查毒啊,其他什么也不可以啊

TOP

说的太笼统了吧。怎么没法用?!没反映?!
默默祈祷,愿世界无灾无难,望天下无事无非~

TOP

复制内容到剪贴板
代码:
2007-06-12,22:04:07

System Repair Engineer 2.4.12.806
Smallfrogs ([url]http://www.KZTechs.com[/url])

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <KavPFW><"D:\KAV2006\KAVPFW.exe">  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>  [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD."]
    <wallpaper><c:\windows\system32\壁纸自动换.exe>  []
    <nwiz><nwiz.exe /install>  []
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <Supplicant><d:\program files\锐捷网络\ruijie supplicant\8021x.exe>  [锐捷网络]
    <KavStart><"D:\KAV2006\KAVStart.exe" >  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KASTask><C:\PROGRA~1\KOS\KASTask.EXE>  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll>  [北京三七二一科技有限公司]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <SysTime><C:\PROGRA~1\WinKld\WinKld.dll>  [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\System32\logon.scr>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
  <D:\KAV2006\KWatch.EXE><Kingsoft Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
  <"D:\KAV2006\KPfwSvc.EXE"><Kingsoft Corporation>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[CnsMinKP / CnsMinKP][Running/Boot Start]
  <\SystemRoot\system32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[NVATABUS / NVATABUS][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\NVATABUS.SYS><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
  <system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
[NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
  <system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
[perfs / perfs][Running/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\perfs.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[R2A / R2A][Stopped/Disabled]
  <\??\C:\WINDOWS\system32a2.sys><N/A>
[PCANDIS5 NDIS Protocol Driver / PCANDIS5][Running/Manual Start]
  <\??\C:\WINDOWS\system32\PCANDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
[KWatch3 / KWatch3][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[KNetWch / KNetWch][Running/System Start]
  <\??\D:\KAV2006\KNetWch.SYS><Kingsoft Corporation>
[ATSpy / ATSpy][Running/Manual Start]
  <\??\C:\WINDOWS\system32\ATSpy.sys><N/A>

==================================
浏览器加载项
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[CBrowseStakeout Class]
  {55302805-482E-470E-8A57-6795A1487F90} <D:\KAV2006\KAVAFish.DLL, Kingsoft Corporation>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[豪杰超级解霸9]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <d:\Program Files\Herosoft\Hero 9\STHSDVD.EXE, herosoft>
[Yahoo 3.5G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail[/url], N/A>
[名品折扣]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <[url]http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138[/url],140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist[/url], N/A>
[雅虎WIDGET]
  {6354ABE6-05F1-49ed-B850-E423120EC338} <[url]http://cn.widget.yahoo.com/index.htm?source=Cns[/url], N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg[/url], N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair[/url], N/A>
[精彩图铃]
  {EE60714F-AC27-427e-861A-FD60CBDF119A} <[url]http://click2.ad4all.net/url2/urlmanage/url.asp?id=163[/url], N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean[/url], N/A>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[金山毒霸在线产品升级]
  {E847C78C-C210-4195-8799-FBF3BF89797D} <C:\PROGRA~1\KOS\KOSInit.OCX, 金山软件股份有限公司>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[CBrowseStakeout Class]
  {55302805-482E-470E-8A57-6795A1487F90} <D:\KAV2006\KAVAFish.DLL, Kingsoft Corporation>
[金山毒霸在线杀毒]
  {577A1997-6FD0-4972-B234-885DA583F9CE} <C:\PROGRA~1\KOS\KOSClean.OCX, 金山软件股份有限公司>
[DragSearch BHO]
  {62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[AutoLive]
  {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, 北京三七二一科技有限公司>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9a.ocx, Adobe Systems, Inc.>
[金山毒霸在线产品升级]
  {E847C78C-C210-4195-8799-FBF3BF89797D} <C:\PROGRA~1\KOS\KOSInit.OCX, 金山软件股份有限公司>
[使用超级解霸播放]
  <d:\Program Files\Herosoft\Hero 9\MPURLGET.HTM, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到雅虎收藏+]
  <[url]http://myweb.cn.yahoo.com/post.html?F=D2_A[/url], N/A>
[精彩图铃]
  <C:\Program Files\AD4All\link2\phone.htm, N/A>
[金山毒霸反钓鱼...]
  <D:\KAV2006\KAF\ShowSet.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>

==================================
正在运行的进程
[PID: 592][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 660][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 684][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 728][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 888][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1044][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1396][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\PROGRA~1\3721\alrex.dll]  [, 2.5.0.1002]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\PROGRA~1\3721\autolive.dll]  [北京三七二一科技有限公司, 2.5.4.1009]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [, 2, 2, 0, 1050]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [ , 2, 0, 1, 1007]
    [C:\WINDOWS\system32\cacb.dll]  [N/A, ]
    [C:\WINDOWS\system32\HttpReq.dll]  [N/A, ]
    [C:\WINDOWS\system32\WebDLL.dll]  [N/A, ]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll]  [, 1, 0, 1, 1014]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [D:\KAV2006\KAVEXT.DLL]  [Kingsoft Corporation, 2007, 5, 11, 28]
[PID: 284][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 52]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 624][D:\program files\锐捷网络\ruijie supplicant\8021x.exe]  [锐捷网络, 2, 56, 0, 0]
    [C:\WINDOWS\system32\W32N50.dll]  [Printing Communications Assoc., Inc. (PCAUSA), 5.03.16.54]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 656][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 1928][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 1244][C:\Program Files\QQ2006\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\QQ2006\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 160]
    [C:\Program Files\QQ2006\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\QQ2006\PYKer.dll]  [飘云 [url]http://www.pyqq.cn[/url], 飘云]
    [C:\Program Files\QQ2006\ipsearcher.dll]  [, 1.0.0.3]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\Program Files\QQ2006\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\QQ2006\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\Program Files\QQ2006\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\QQ2006\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 3, 2, 1]
    [C:\Program Files\QQ2006\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\QQ2006\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQMainFrame.dll]  [N/A, ]
    [C:\Program Files\QQ2006\CQQApplication.dll]  [N/A, ]
    [C:\Program Files\QQ2006\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [C:\Program Files\QQ2006\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\QQ2006\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\GroupLive.dll]  [N/A, ]
    [C:\Program Files\QQ2006\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQPlugin.dll]  [N/A, ]
    [C:\Program Files\QQ2006\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QRingMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\QQ2006\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\QQ2006\QQAvatar.dll]  [N/A, ]
    [C:\Program Files\QQ2006\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\QQ2006\ShareFiles.dll]  [N/A, ]
    [C:\Program Files\QQ2006\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\QQ2006\QQSysMsgMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\QQAllInOne.dll]  [N/A, ]
    [C:\Program Files\QQ2006\SCCore.dll]  [N/A, ]
    [C:\Program Files\QQ2006\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\QQ2006\QQCustomFace.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9a.ocx]  [Adobe Systems, Inc., 9,0,0,296]
    [C:\Program Files\QQ2006\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\QQ2006\QQSceneMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\BQQApplication.dll]  [N/A, ]
    [C:\Program Files\QQ2006\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\Program Files\QQ2006\QQSettingCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQUdpGetFileLib.dll]  [tencent, 0, 2, 2, 3]
    [C:\Program Files\QQ2006\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
    [C:\Program Files\QQ2006\QQFileTransfer.dll]  [Tencent, 5, 0, 202, 180]
    [C:\Program Files\QQ2006\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
    [C:\WINDOWS\system32\msadp32.acm]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\QQ2006\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\GroupConnection.dll]  [Tencent, 5, 0, 202, 170]
[PID: 200][C:\Program Files\QQ2006\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [, 2, 0, 9, 1027]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3892][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 3628][D:\KAV2006\KAV32.EXE]  [Kingsoft Corporation, 2005, 11, 24, 2008]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [D:\KAV2006\KAV32Res.dll]  [Kingsoft Corporation, 2007, 4, 28, 111]
    [D:\KAV2006\KAEPlat.DLL]  [Kingsoft Corp., 2006, 8, 29, 60]
    [D:\KAV2006\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
    [D:\KAV2006\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 5, 9, 120]
    [D:\KAV2006\KAConfig.DLL]  [Kingsoft Corporation, 2007, 1, 11, 41]
    [D:\KAV2006\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
[PID: 2304][C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe]  [Yahoo! China, 2, 0, 7, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [, 2, 0, 9, 1027]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [, 2, 2, 0, 1050]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [ , 2, 0, 1, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Ynotifier.dll]  [, 1, 0, 0, 5]
[PID: 3268][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\WINDOWS\DOWNLO~1\CnsHint.dll]  [3721, 2, 5, 0, 2]
    [C:\WINDOWS\DOWNLO~1\cnsplus.dll]  [3721, 2, 5, 0, 2]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  [Yahoo!, 2, 2, 0, 1050]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  [Yahoo, 1, 0, 2, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  [Yahoo, 1, 0, 4, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  [, 1, 1, 4, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  [Yahoo, 1, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]  [Yahoo! China, 1, 1, 3, 1035]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll]  [Yahoo! China, 1, 0, 1, 1015]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll]  [Yahoo., 1, 0, 9, 1010]
    [D:\KAV2006\KAVAFish.DLL]  [Kingsoft Corporation, 2006, 10, 25, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [, 1, 2, 7, 1006]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\WINABCX.IME]  [PKUETI, 5.22.216]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  [ , 1, 0, 3, 1002]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll]  [Yahoo, 1, 0, 9, 1322]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll]  [Yahoo, 1, 0, 1, 1001]
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  [Yahoo, 1, 0, 3, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yXPStyle.dll]  [Yahoo, 1, 0, 2, 1309]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.2906 (xpsp_sp2_gdr.060510-2351)]
[PID: 2732][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.2.0.207]
    [C:\Program Files\Thunder Network\Thunder\Program\updatedownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 1, 0, 3, 70]
    [C:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [N/A, ]
    [C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
    [C:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 7]
    [C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 5]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed.dll]  [ , 2, 1, 0, 29]
    [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 60]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2224][C:\Documents and Settings\Administrator\桌面\sreng.exe]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1       localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================

TOP

这个可以吗?要什么样的才行啊!!!!!!!!!!!

TOP

这个可以吗?要什么样的才行啊!!!!!!!!!!!

TOP

具体就是用了"av终结者"杀不出毒来,但是机子还是和av中毒的时候是一样的,谢谢

TOP

用了AV终结者也没用,每次都弹出KAV32.EXE--应用程序错误,应用程序正常初始化(0xc00000ba)失败!!!毒霸 根本起用不了...

TOP

最新的病毒资讯,最简单有效的手工处理方案,尽在计算机安全资讯网

TOP

;金山清理专家系统诊断报告
;诊断时间: 2007-6-12
;诊断平台: Windows XP [5.1.2600] Service Pack 2
;IE浏览器版本: Internet Explorer V6.0.2180.2900
;该诊断报告由金山清理专家生成 http://www.duba.net


; 开始菜单启动目录
11 - F:\CAJViewer.exe - (NULL) - 0.0.0.0

; 开机自启动程序
38 - C:\Program Files\Rising\AntiSpyware\runiep.exe - Beijing Rising Technology Co., Ltd. - 1.0.1.6
38 - C:\KAV2007\KAVStart.exe - Kingsoft Corporation - 2007.5.9.272
38 - C:\WINDOWS\system32\drivers\svchost.exe - (NULL) - 0.0.0.0
38 - D:\迅雷\Thunder.exe - Thunder Networking Technologies,LTD - 5.6.3.12
38 - C:\KAV2007\KAVPFW.exe - Kingsoft Corporation - 2005.9.19.4
38 - C:\Program Files\Rising\AntiSpyware\RunOnce.exe - Beijing Rising Technology Co., Ltd. - 19.0.0.2

; 浏览器辅助对象(BHO)
41 - C:\KAV2007\KAVAFish.DLL - Kingsoft Corporation - 2006.10.25.27

; 系统服务
60 - E:\SAN11\RISING\RAV\Ravmond.exe - (NULL) - 0.0.0.0
60 - E:\san11\Rising\Rav\CCenter.exe - (NULL) - 0.0.0.0
60 - C:\KAV2007\KWatch.EXE - Kingsoft Corporation - 2007.2.12.84
60 - C:\KAV2007\KPfwSvc.EXE - Kingsoft Corporation - 2007.2.2.31
60 - C:\WINDOWS\System32\hidserv.dll - (NULL) - 0.0.0.0

; 当前进程
50 - D:\迅雷\Program\Thunder5.exe - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Program\Thunder5.exe - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Program\TaskManager.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Program\download_interface.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Program\stlport_vc646.dll - STLport Consulting, Inc. - 5.6.3.307
    51 - D:\迅雷\Program\asyn_dns.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Program\BHOStub.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\DownAndPlay\DownAndPlay.dll - (NULL) - 5.6.3.307
    51 - C:\Program Files\Rising\AntiSpyware\ieprot.dll - Beijing Rising Technology Co., Ltd. - 5.6.3.307
    51 - D:\迅雷\Program\iTargetAD.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\InMedia\iEmbedShell.dll -   - 5.6.3.307
    51 - D:\迅雷\Components\Community\XLCommunity.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\Security\ThunderSafe.dll - 深圳市迅雷网络技术有限公司 - 5.6.3.307
    51 - D:\迅雷\Components\Search\XLSearch.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\P4PClient\P4PClient.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Program\LiveUpdate.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\ExplorerHelper\ExplorerHelper.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\Tips\TipsClient.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\VPSHELL\VPSHELL.dll - XunLei - 5.6.3.307
    51 - D:\迅雷\Components\UserExperience\UserExperience.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\ResWorker\DsXlCom.dll - (NULL) - 5.6.3.307
    51 - D:\迅雷\Components\InMedia\iEmbed10.dll -   - 5.6.3.307
    51 - D:\迅雷\Program\RegisterDll.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Program\MSVCIRT.dll - Microsoft Corporation - 5.6.3.307
    51 - D:\迅雷\Program\XLNet.Dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Plugins\TingTing\TingTing.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Plugins\BhoAdv\bho_adv.dll - 深圳市迅雷网络技术有限公司 - 5.6.3.307
    51 - D:\迅雷\ComDlls\ThunderAgent_Now.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\VPSHELL\VideoPicture.dll - XunLei - 5.6.3.307
    51 - D:\迅雷\Components\ResWorker\DataProcessor_01.dll - Thunder Networking Technologies,LTD - 5.6.3.307
    51 - D:\迅雷\Components\ResWorker\MediaWorker.dll - Thunder Networking Technologies,LTD - 5.6.3.307
50 - C:\Program Files\MathType\MathType.exe - Design Science, Inc. - 2003.11.13.1
    51 - C:\Program Files\MathType\MathType.exe - Design Science, Inc. - 2003.11.13.1
    51 - C:\Program Files\Rising\AntiSpyware\ieprot.dll - Beijing Rising Technology Co., Ltd. - 2003.11.13.1
50 - C:\KAV2007\KPfwSvc.EXE - Kingsoft Corporation - 2007.2.2.31
50 - C:\Program Files\Rising\AntiSpyware\runiep.exe - Beijing Rising Technology Co., Ltd. - 1.0.1.6
    51 - C:\Program Files\Rising\AntiSpyware\runiep.exe - Beijing Rising Technology Co., Ltd. - 1.0.1.6
    51 - C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll - Beijing Rising Technology Co., Ltd. - 1.0.1.6
    51 - C:\Program Files\Rising\AntiSpyware\ieprot.dll - Beijing Rising Technology Co., Ltd. - 1.0.1.6
50 - C:\KAV2007\KWatch.EXE - Kingsoft Corporation - 2007.2.12.84

TOP

谢谢 小空 的意见 现在可以启动了!!谢谢!
期待 毒霸 能够尽快阻止这种 叫人崩溃的病毒...举报下:我的病毒都是由U盘传送的,因为我现在正在做毕业设计,同学们也是,很多人在机房用了后回来一插 就出 问题 ...期待能加强USB口的控制哈!!

TOP

发新话题