发新话题
打印

[求助] 求助!进程里运行asgwmne.exe和eleicnd.exe两个莫名进程

求助!进程里运行asgwmne.exe和eleicnd.exe两个莫名进程

进程里运行有asgwmne.exe和eleicnd.exe两个莫名进程,路径:C:\Program Files\Common Files\System\asgwmne.exe 另一个:C:\Program Files\Common Files\Microsoft Shared\eleicnd.exe 每打进杀毒软件和这两个进程的文件夹就会自动关闭。有些exe文件运行不了,系统提示:不是win32有效应用文件。此问题重装也不行。我尝试过把硬盘拆到另一台机杀毒,但运行杀毒软件不久就蓝屏,重开机后发现那台机也感染了那病毒。病态一模一样!请问各位高手此病毒如何解决??

TOP

把样本传上来吧。
推荐最好用的毒霸删除工具,删除病毒、备份样本,一次完成,请将备份病毒的文件夹“_BackUp_”打包上传到样本上传区

请新会员关注新手杀毒入门
提问贴注意详细描述现象、操作过程,如果是病毒报告,应说明病毒名,染毒文件路径、文件名等,请注意不要只发一个LOG,发贴太简单将不能得到正确的答案。

TOP

复制内容到剪贴板
代码:
2007-06-12,22:04:07

System Repair Engineer 2.4.12.806
Smallfrogs ([url]http://www.KZTechs.com[/url])

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <KavPFW><"D:\KAV2006\KAVPFW.exe">  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>  [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD."]
    <wallpaper><c:\windows\system32\壁纸自动换.exe>  []
    <nwiz><nwiz.exe /install>  []
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <Supplicant><d:\program files\锐捷网络\ruijie supplicant\8021x.exe>  [锐捷网络]
    <KavStart><"D:\KAV2006\KAVStart.exe" >  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KASTask><C:\PROGRA~1\KOS\KASTask.EXE>  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll>  [北京三七二一科技有限公司]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <SysTime><C:\PROGRA~1\WinKld\WinKld.dll>  [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\System32\logon.scr>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
  <D:\KAV2006\KWatch.EXE><Kingsoft Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
  <"D:\KAV2006\KPfwSvc.EXE"><Kingsoft Corporation>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[CnsMinKP / CnsMinKP][Running/Boot Start]
  <\SystemRoot\system32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[NVATABUS / NVATABUS][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\NVATABUS.SYS><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
  <system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
[NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
  <system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
[perfs / perfs][Running/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\perfs.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[R2A / R2A][Stopped/Disabled]
  <\??\C:\WINDOWS\system32a2.sys><N/A>
[PCANDIS5 NDIS Protocol Driver / PCANDIS5][Running/Manual Start]
  <\??\C:\WINDOWS\system32\PCANDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
[KWatch3 / KWatch3][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[KNetWch / KNetWch][Running/System Start]
  <\??\D:\KAV2006\KNetWch.SYS><Kingsoft Corporation>
[ATSpy / ATSpy][Running/Manual Start]
  <\??\C:\WINDOWS\system32\ATSpy.sys><N/A>

==================================
浏览器加载项
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[CBrowseStakeout Class]
  {55302805-482E-470E-8A57-6795A1487F90} <D:\KAV2006\KAVAFish.DLL, Kingsoft Corporation>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[豪杰超级解霸9]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <d:\Program Files\Herosoft\Hero 9\STHSDVD.EXE, herosoft>
[Yahoo 3.5G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail[/url], N/A>
[名品折扣]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <[url]http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138[/url],140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist[/url], N/A>
[雅虎WIDGET]
  {6354ABE6-05F1-49ed-B850-E423120EC338} <[url]http://cn.widget.yahoo.com/index.htm?source=Cns[/url], N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg[/url], N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair[/url], N/A>
[精彩图铃]
  {EE60714F-AC27-427e-861A-FD60CBDF119A} <[url]http://click2.ad4all.net/url2/urlmanage/url.asp?id=163[/url], N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean[/url], N/A>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[金山毒霸在线产品升级]
  {E847C78C-C210-4195-8799-FBF3BF89797D} <C:\PROGRA~1\KOS\KOSInit.OCX, 金山软件股份有限公司>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[CBrowseStakeout Class]
  {55302805-482E-470E-8A57-6795A1487F90} <D:\KAV2006\KAVAFish.DLL, Kingsoft Corporation>
[金山毒霸在线杀毒]
  {577A1997-6FD0-4972-B234-885DA583F9CE} <C:\PROGRA~1\KOS\KOSClean.OCX, 金山软件股份有限公司>
[DragSearch BHO]
  {62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[AutoLive]
  {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, 北京三七二一科技有限公司>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9a.ocx, Adobe Systems, Inc.>
[金山毒霸在线产品升级]
  {E847C78C-C210-4195-8799-FBF3BF89797D} <C:\PROGRA~1\KOS\KOSInit.OCX, 金山软件股份有限公司>
[使用超级解霸播放]
  <d:\Program Files\Herosoft\Hero 9\MPURLGET.HTM, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到雅虎收藏+]
  <[url]http://myweb.cn.yahoo.com/post.html?F=D2_A[/url], N/A>
[精彩图铃]
  <C:\Program Files\AD4All\link2\phone.htm, N/A>
[金山毒霸反钓鱼...]
  <D:\KAV2006\KAF\ShowSet.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>

==================================
正在运行的进程
[PID: 592][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 660][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 684][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 728][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 888][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1044][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1396][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\PROGRA~1\3721\alrex.dll]  [, 2.5.0.1002]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\PROGRA~1\3721\autolive.dll]  [北京三七二一科技有限公司, 2.5.4.1009]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [, 2, 2, 0, 1050]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [ , 2, 0, 1, 1007]
    [C:\WINDOWS\system32\cacb.dll]  [N/A, ]
    [C:\WINDOWS\system32\HttpReq.dll]  [N/A, ]
    [C:\WINDOWS\system32\WebDLL.dll]  [N/A, ]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll]  [, 1, 0, 1, 1014]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [D:\KAV2006\KAVEXT.DLL]  [Kingsoft Corporation, 2007, 5, 11, 28]
[PID: 284][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 52]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 624][D:\program files\锐捷网络\ruijie supplicant\8021x.exe]  [锐捷网络, 2, 56, 0, 0]
    [C:\WINDOWS\system32\W32N50.dll]  [Printing Communications Assoc., Inc. (PCAUSA), 5.03.16.54]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 656][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 1928][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 1244][C:\Program Files\QQ2006\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\QQ2006\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 160]
    [C:\Program Files\QQ2006\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\QQ2006\PYKer.dll]  [飘云 [url]http://www.pyqq.cn[/url], 飘云]
    [C:\Program Files\QQ2006\ipsearcher.dll]  [, 1.0.0.3]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\Program Files\QQ2006\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\QQ2006\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [C:\Program Files\QQ2006\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\QQ2006\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 3, 2, 1]
    [C:\Program Files\QQ2006\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\QQ2006\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQMainFrame.dll]  [N/A, ]
    [C:\Program Files\QQ2006\CQQApplication.dll]  [N/A, ]
    [C:\Program Files\QQ2006\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [C:\Program Files\QQ2006\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\QQ2006\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\GroupLive.dll]  [N/A, ]
    [C:\Program Files\QQ2006\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQPlugin.dll]  [N/A, ]
    [C:\Program Files\QQ2006\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QRingMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\QQ2006\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\QQ2006\QQAvatar.dll]  [N/A, ]
    [C:\Program Files\QQ2006\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\QQ2006\ShareFiles.dll]  [N/A, ]
    [C:\Program Files\QQ2006\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\QQ2006\QQSysMsgMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\QQAllInOne.dll]  [N/A, ]
    [C:\Program Files\QQ2006\SCCore.dll]  [N/A, ]
    [C:\Program Files\QQ2006\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\QQ2006\QQCustomFace.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9a.ocx]  [Adobe Systems, Inc., 9,0,0,296]
    [C:\Program Files\QQ2006\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\QQ2006\QQSceneMng.dll]  [N/A, ]
    [C:\Program Files\QQ2006\BQQApplication.dll]  [N/A, ]
    [C:\Program Files\QQ2006\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\Program Files\QQ2006\QQSettingCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\QQUdpGetFileLib.dll]  [tencent, 0, 2, 2, 3]
    [C:\Program Files\QQ2006\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
    [C:\Program Files\QQ2006\QQFileTransfer.dll]  [Tencent, 5, 0, 202, 180]
    [C:\Program Files\QQ2006\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
    [C:\WINDOWS\system32\msadp32.acm]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\QQ2006\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\QQ2006\GroupConnection.dll]  [Tencent, 5, 0, 202, 170]
[PID: 200][C:\Program Files\QQ2006\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [, 2, 0, 9, 1027]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\Program Files\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3892][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
[PID: 3628][D:\KAV2006\KAV32.EXE]  [Kingsoft Corporation, 2005, 11, 24, 2008]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [D:\KAV2006\KAV32Res.dll]  [Kingsoft Corporation, 2007, 4, 28, 111]
    [D:\KAV2006\KAEPlat.DLL]  [Kingsoft Corp., 2006, 8, 29, 60]
    [D:\KAV2006\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
    [D:\KAV2006\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 5, 9, 120]
    [D:\KAV2006\KAConfig.DLL]  [Kingsoft Corporation, 2007, 1, 11, 41]
    [D:\KAV2006\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
[PID: 2304][C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe]  [Yahoo! China, 2, 0, 7, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [, 2, 0, 9, 1027]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  [, 2, 2, 0, 1050]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [ , 2, 0, 1, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Ynotifier.dll]  [, 1, 0, 0, 5]
[PID: 3268][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\WINDOWS\DOWNLO~1\CnsHint.dll]  [3721, 2, 5, 0, 2]
    [C:\WINDOWS\DOWNLO~1\cnsplus.dll]  [3721, 2, 5, 0, 2]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  [Yahoo!, 2, 2, 0, 1050]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  [Yahoo, 1, 0, 2, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  [Yahoo, 1, 0, 4, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  [, 1, 1, 4, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  [Yahoo, 1, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]  [Yahoo! China, 1, 1, 3, 1035]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll]  [Yahoo! China, 1, 0, 1, 1015]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll]  [Yahoo., 1, 0, 9, 1010]
    [D:\KAV2006\KAVAFish.DLL]  [Kingsoft Corporation, 2006, 10, 25, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [, 1, 2, 7, 1006]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
    [C:\WINDOWS\system32\WINABCX.IME]  [PKUETI, 5.22.216]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  [ , 1, 0, 3, 1002]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll]  [Yahoo, 1, 0, 9, 1322]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll]  [Yahoo, 1, 0, 1, 1001]
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  [Yahoo, 1, 0, 3, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yXPStyle.dll]  [Yahoo, 1, 0, 2, 1309]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.2906 (xpsp_sp2_gdr.060510-2351)]
[PID: 2732][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.2.0.207]
    [C:\Program Files\Thunder Network\Thunder\Program\updatedownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 1, 0, 3, 70]
    [C:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [N/A, ]
    [C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
    [C:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]
    [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 7]
    [C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 5]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed.dll]  [ , 2, 1, 0, 29]
    [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.1.5]
    [C:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 60]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2224][C:\Documents and Settings\Administrator\桌面\sreng.exe]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.0.9]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1       localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================

TOP

就是这个东西,不知道是什么,杀毒一开就关了,怀疑是变种

TOP

楼上的朋友,你是什么问题,请单独发帖,谢谢。
默默祈祷,愿世界无灾无难,望天下无事无非~

TOP

好的,我的可能是种了av终结者的变种,我已经发了新的帖子,没人回啊

TOP

用SRENG删除启动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll>  [北京三七二一科技有限公司]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <SysTime><C:\PROGRA~1\WinKld\WinKld.dll>  [N/A]

用SRENG删除驱动:(如不能删除请设置启动类型为Disable)
[perfs / perfs][Running/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\perfs.sys><N/A>
[R2A / R2A][Stopped/Disabled]
  <\??\C:\WINDOWS\system32a2.sys><N/A>
用xdelbox复制以下路径删除:
(XDelBox下载)
c:\windows\DOWNLO~1\CnsMin.dll
c:\windows\DOWNLO~1\CnsHook.dll
c:\PROGRA~1\WinKld\WinKld.dll
c:\windows\system32\drivers\perfs.sys
c:\windows\system32a2.sys

用下面软件清理(下载后,请升级到最新版本)
奇虎安全卫士:http://www.360safe.com/
金山毒霸清理专家:http://www.digit.lxdns.com/duba/ ... 16/KASSetup0415.exe
windows清理助手:http://www.arswp.com/download/arswp/arswp.rar
尽我所能帮助我能帮助的中毒患者

TOP

我也有这样的情况!用AV终结者根本不起作用

TOP

你可以看看这个帖子

TOP

你参考下这个帖子
应该是差不多的吧
http://user.qzone.qq.com/275663595
我同事上次电脑上出现的是“进程hmbduoj.exe和tygxhqb.exe”

TOP

发新话题