29 12
发新话题
打印

[求助] 菜鸟急救!NTVDM CPU无效指令(系统异常080719by cchao21)

菜鸟急救!NTVDM CPU无效指令(系统异常080719by cchao21)

语言栏不见了!!
控制面板的那个高级语言设置总是关闭的,怎么打也打不开,而且电脑总是出现

NTVDM CPU 遇到无效指令 ……

怎么回事啊啊!!救救我吧!重做系统也不好使!杀毒也杀不了

[ 本帖最后由 cchao21 于 2008-7-19 22:56 编辑 ]

TOP

将%windir%\system32下ctfmon.exe打包上传,并找一份同版本干净文件覆盖

TOP

先进行查杀下,再处理系统异常。
运行金山清理专家,清理后上传报告分析下。
http://bbs.duba.net/thread-21915967-1-1.html
->恶意软件查杀
-->在线系统诊断-->导出诊断报告-->勾选 隐藏所有已知安全的项+全选-->导出报告
全选,复制,贴报告
注意:请说明病毒具体路径

TOP

引用:
NTVDM CPU 遇到无效指令 ……
光凭这点就基本可以确定是中毒了...

按照 3# 说的做吧

TOP

快救救我555

==============================================================
        金山清理专家系统诊断报告
该诊断报告由金山清理专家提供 http://www.duba.net
==============================================================
诊断时间:            2000-07-20, 11:01
诊断平台:            Windows XP [5.1.2600] Service Pack 2
IE版本:              Internet Explorer V6.0.2180.2900
计算机物理内存:      511(MB)
当前可用内存:        182(MB)
硬盘总大小:          37(GB)
硬盘可用空间:        23(GB)
清理专家版本:        2008.07.16.472
恶意软件库版本:      2008.07.17.2
漏洞库版本:          2008.07.17.1


==============================================================
        启动文件夹位置
==============================================================
Common Startup:      C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Startup:             C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
Common Startup:      %ALLUSERSPROFILE%\「开始」菜单\程序\启动
==============================================================
        Host File
==============================================================
127.0.0.1       localhost
==============================================================
        系统服务
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
        [HidServ] [已禁用]             <%SystemRoot%\System32\hidserv.dll>
        [HWSuperPowerTablet] [已启用]  <C:\WINDOWS\system32\JWPEN.exe>
        文件路径: C:\WINDOWS\system32\JWPEN.exe [服务器忙]

==============================================================
        驱动程序
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
        [vidc.ffds] [已启用]           <ff_vfw.dll>
        文件路径: C:\WINDOWS\system32\ff_vfw.dll [服务器忙]
        [vidc.xivd] [已启用]           <C:\Program Files\StormII\codec\xvidvfw.dll>
        文件路径: C:\Program Files\StormII\codec\xvidvfw.dll [服务器忙]
        [vidc.tscc] [已启用]           <C:\WINDOWS\system32\tsccvid.dll>
        文件路径: C:\WINDOWS\system32\tsccvid.dll [服务器忙]
        [vidc.VP60] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP61] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP62] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP6F] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.FLV4] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP70] [已启用]           <C:\WINDOWS\system32\vp7vfw.dll>
        文件路径: C:\WINDOWS\system32\vp7vfw.dll [服务器忙]
        [VIDC.FPS1] [已启用]           <frapsvid.dll>
        文件路径: C:\WINDOWS\system32\frapsvid.dll [服务器忙]
        [VIDC.VMnc] [已启用]           <vmnc.dll>
        文件路径: C:\WINDOWS\system32\vmnc.dll [服务器忙]
        [vidc.aasc] [已启用]           <aasc32.dll>
        文件路径: C:\WINDOWS\system32\aasc32.dll [服务器忙]
        [vidc.aas4] [已启用]           <aasc32.dll>
        文件路径: C:\WINDOWS\system32\aasc32.dll [服务器忙]
        [vidc.UCDO] [已启用]           <clrviddd.dll>
        文件路径: C:\WINDOWS\system32\clrviddd.dll [服务器忙]
        [vidc.LEAD] [已启用]           <LCODCCMP.DLL>
        文件路径: C:\WINDOWS\system32\LCODCCMP.DLL [服务器忙]
        [vidc.avrn] [已启用]           <avidavicodec.dll>
        文件路径: C:\WINDOWS\system32\avidavicodec.dll [服务器忙]
        [vidc.advj] [已启用]           <avidavicodec.dll>
        文件路径: C:\WINDOWS\system32\avidavicodec.dll [服务器忙]
        [vidc.asv1] [已启用]           <asusasv1.dll>
        文件路径: C:\WINDOWS\system32\asusasv1.dll [服务器忙]
        [vidc.asv2] [已启用]           <asusasv2.dll>
        文件路径: C:\WINDOWS\system32\asusasv2.dll [服务器忙]
        [vidc.asvx] [已启用]           <asusasv2.dll>
        文件路径: C:\WINDOWS\system32\asusasv2.dll [服务器忙]
        [vidc.vdom] [已启用]           <vdowave.drv>
        文件路径: C:\WINDOWS\system32\vdowave.drv [服务器忙]
        [vidc.I263] [已启用]           <i263_32.drv>
        文件路径: C:\WINDOWS\system32\i263_32.drv [服务器忙]
        [vidc.VCR2] [已启用]           <ativcr2.dll>
        文件路径: C:\WINDOWS\system32\ativcr2.dll [服务器忙]
        [vidc.lsvx] [已启用]           <lsvxdec.dll>
        文件路径: C:\WINDOWS\system32\lsvxdec.dll [服务器忙]
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
        [4f2698e489d3abf1] [已启用]    <\??\C:\4f2698e489d3abf1.dat>
        [AmdK8] [已启用]               <System32\DRIVERS\amdk8.sys>
        文件路径: C:\WINDOWS\system32\DRIVERS\amdk8.sys [服务器忙]
        [apcdli] [已启用]              <\??\C:\Program Files\Microsoft Office\SYSTEM\apcdli.sys>
        [cb1e94f0b8696d31] [已启用]    <\??\C:\cb1e94f0b8696d31.dat>
        [HiddFldy] [已启用]            <\??\C:\WINDOWS\system32\d32dx9.sys>
        [hypen] [已启用]               <System32\Drivers\hypen.sys>
        文件路径: C:\WINDOWS\system32\Drivers\hypen.sys [服务器忙]
        [msiffei] [已启用]             <System32\Drivers\msiffei.sys>
        文件路径: C:\WINDOWS\system32\Drivers\msiffei.sys [服务器忙]
        [ntptdb] [已启用]              <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys>
        文件路径: C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys [服务器忙]
        [sjmcmlnkap] [已启用]          <System32\DRIVERS\sjmcmlnkap.sys>
        文件路径: C:\WINDOWS\system32\DRIVERS\sjmcmlnkap.sys [服务器忙]
        [Tcpip] [已启用]               <system32\DRIVERS\tcpip.sys/TCP/IP Protocol Driver>
        文件路径: C:\WINDOWS\system32\DRIVERS\tcpip.sys [服务器忙]

==============================================================
        BHO
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
        [InceHelper Class]
        {986488AF-13D5-9DDF-4FEF-9FB88698CFC1}  <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll>
        文件路径: C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll [分析中]

==============================================================
        当前进程
==============================================================
名称:     winlogon.exe  [已启用]
该项来源: \??\C:\WINDOWS\system32\winlogon.exe
命令行:   winlogon.exe
文件路径: C:\WINDOWS\system32\winlogon.exe  [服务器忙]      (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ntdll.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\AUTHZ.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\CRYPT32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSASN1.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NDdeApi.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\PROFMAP.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NETAPI32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USERENV.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\PSAPI.DLL                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\REGAPI.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SETUPAPI.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\VERSION.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSTA.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINTRUST.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMAGEHLP.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2_32.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WS2HELP.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL                   (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSGINA.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMCTL32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ODBC32.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comdlg32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\odbcint.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHSVCS.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\sfc.dll                   (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\sfc_os.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Apphelp.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msctfime.ime              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSCARD.DLL              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WTSAPI32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINMM.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\sxs.dll                   (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Ati2evxx.dll              (ATI Technologies Inc.)
模块文件: C:\WINDOWS\system32\OLEAUT32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\rsaenh.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\cscdll.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WlNotify.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSPOOL.DRV              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MPR.dll                   (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SAMLIB.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msv1_0.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\iphlpapi.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SOGOUPY.IME               (Sohu.com Inc.)
模块文件: C:\WINDOWS\system32\WININET.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSIMG32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\NTMARTA.DLL               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WLDAP32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\cscui.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\wdmaud.drv                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msacm32.drv               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSACM32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\midimap.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMRes.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\CLBCATQ.DLL               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\xpsp2res.dll              (Microsoft Corporation)
名称:     JWPEN.exe  [已启用]
文件路径: C:\WINDOWS\system32\JWPEN.exe  [服务器忙]         (HanWang)
模块文件: C:\WINDOWS\system32\ntdll.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kernel32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\HID.DLL                   (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\msvcrt.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ADVAPI32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\RPCRT4.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\Secur32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SETUPAPI.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\GDI32.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USER32.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\comdlg32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHLWAPI.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\COMCTL32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\SHELL32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINSPOOL.DRV              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\oledlg.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\ole32.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\OLEPRO32.DLL              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\OLEAUT32.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMM32.DLL                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\LPK.DLL                   (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\USP10.dll                 (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\kmon.dll                  (Beijing Rising Technology Co.. Ltd.)
模块文件: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\urlmon.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\VERSION.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\uxtheme.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\WINTRUST.dll              (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\CRYPT32.dll               (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\MSASN1.dll                (Microsoft Corporation)
模块文件: C:\WINDOWS\system32\IMAGEHLP.dll              (Microsoft Corporation)

==============================================================
        ActiveX控件
==============================================================
该项来源: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
        [InceHelper Class]
        <{986488AF-13D5-9DDF-4FEF-9FB88698CFC1}>        <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll>
        文件路径: C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll [分析中]

==============================================================
        其他安全区域
==============================================================
该项来源: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
        [显示摇曳 CPL 扩展]         <deskpan.dll>
        [WinRAR]              <C:\Program Files\WinRAR\rarext.dll>
        文件路径: C:\Program Files\WinRAR\rarext.dll [服务器忙]

TOP

应该是木马群
楼主能不能上传SREng的日志?
扫日志前关闭无用进程,如QQ,迅雷

到大的软件站,如天空,太平洋,下载2.6正式版版的SReng(推荐)

http://www.skycn.com/soft/45002.html
SREng/智能扫描

等扫描完成,保存日志(LOG格式)
日志以附件上传,贴到反病毒区或流行病毒区
PS:如主程序SREng**.exe无法运行,导致无法扫描日志
运交华盖欲何求,未敢翻身已碰头;
破帽遮颜过闹市,漏船载酒泛中流。
横眉冷对千夫指,俯首甘为孺子牛;
躲进小楼成一统,管它春夏与冬秋。

TOP

删除以下项并进行清理:
--------------------------------------------------------------
该项来源: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
        [4f2698e489d3abf1] [已启用]    <\??\C:\4f2698e489d3abf1.dat>
[apcdli] [已启用]              <\??\C:\Program Files\Microsoft Office\SYSTEM\apcdli.sys>
        [cb1e94f0b8696d31] [已启用]    <\??\C:\cb1e94f0b8696d31.dat>
        [HiddFldy] [已启用]            <\??\C:\WINDOWS\system32\d32dx9.sys>
        [hypen] [已启用]               <System32\Drivers\hypen.sys>
        文件路径: C:\WINDOWS\system32\Drivers\hypen.sys [服务器忙]
        [msiffei] [已启用]             <System32\Drivers\msiffei.sys>
        文件路径: C:\WINDOWS\system32\Drivers\msiffei.sys [服务器忙]
        [ntptdb] [已启用]              <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys>
        文件路径: C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys [服务器忙]
        [sjmcmlnkap] [已启用]          <System32\DRIVERS\sjmcmlnkap.sys>
        文件路径: C:\WINDOWS\system32\DRIVERS\sjmcmlnkap.sys [服务器忙]

TOP

由于不熟悉金山的日志
只建议清除木马群的DLL
   [vidc.ffds] [已启用]           <ff_vfw.dll>
        文件路径: C:\WINDOWS\system32\ff_vfw.dll [服务器忙]
        [vidc.xivd] [已启用]           <C:\Program Files\StormII\codec\xvidvfw.dll>
        文件路径: C:\Program Files\StormII\codec\xvidvfw.dll [服务器忙]
        [vidc.tscc] [已启用]           <C:\WINDOWS\system32\tsccvid.dll>
        文件路径: C:\WINDOWS\system32\tsccvid.dll [服务器忙]
        [vidc.VP60] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP61] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP62] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP6F] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.FLV4] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP70] [已启用]           <C:\WINDOWS\system32\vp7vfw.dll>
        文件路径: C:\WINDOWS\system32\vp7vfw.dll [服务器忙]
        [VIDC.FPS1] [已启用]           <frapsvid.dll>
        文件路径: C:\WINDOWS\system32\frapsvid.dll [服务器忙]
        [VIDC.VMnc] [已启用]           <vmnc.dll>
        文件路径: C:\WINDOWS\system32\vmnc.dll [服务器忙]
        [vidc.aasc] [已启用]           <aasc32.dll>
        文件路径: C:\WINDOWS\system32\aasc32.dll [服务器忙]
        [vidc.aas4] [已启用]           <aasc32.dll>
        文件路径: C:\WINDOWS\system32\aasc32.dll [服务器忙]
        [vidc.UCDO] [已启用]           <clrviddd.dll>
        文件路径: C:\WINDOWS\system32\clrviddd.dll [服务器忙]
        [vidc.LEAD] [已启用]           <LCODCCMP.DLL>
        文件路径: C:\WINDOWS\system32\LCODCCMP.DLL [服务器忙]
        [vidc.avrn] [已启用]           <avidavicodec.dll>
        文件路径: C:\WINDOWS\system32\avidavicodec.dll [服务器忙]
        [vidc.advj] [已启用]           <avidavicodec.dll>
        文件路径: C:\WINDOWS\system32\avidavicodec.dll [服务器忙]
        [vidc.asv1] [已启用]           <asusasv1.dll>
        文件路径: C:\WINDOWS\system32\asusasv1.dll [服务器忙]
        [vidc.asv2] [已启用]           <asusasv2.dll>
        文件路径: C:\WINDOWS\system32\asusasv2.dll [服务器忙]
        [vidc.asvx] [已启用]           <asusasv2.dll>
        文件路径: C:\WINDOWS\system32\asusasv2.dll [服务器忙]
        [vidc.vdom] [已启用]           <vdowave.drv>
        文件路径: C:\WINDOWS\system32\vdowave.drv [服务器忙]
        [vidc.I263] [已启用]           <i263_32.drv>
        文件路径: C:\WINDOWS\system32\i263_32.drv [服务器忙]
        [vidc.VCR2] [已启用]           <ativcr2.dll>
        文件路径: C:\WINDOWS\system32\ativcr2.dll [服务器忙]
        [vidc.lsvx] [已启用]           <lsvxdec.dll>
        文件路径: C:\WINDOWS\system32\lsvxdec.dll [服务器忙]
运交华盖欲何求,未敢翻身已碰头;
破帽遮颜过闹市,漏船载酒泛中流。
横眉冷对千夫指,俯首甘为孺子牛;
躲进小楼成一统,管它春夏与冬秋。

TOP

SREng的日志

复制内容到剪贴板
代码:
2000-07-20,11:17:53

System Repair Engineer 2.6.11.992
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <PPS Accelerator><C:\Program Files\PPStream\ppsap.exe>  [(Verified)SHANGHAI ZHONGYUAN NETWORKS LIMITED]
    <KavPFW><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPFW32.EXE" -startup>  [(Verified)"Zhuhai  Kingsoft Software Co.,Ltd"]
    <QQDownload><"D:\Program Files\Tencent\QQDownload\QQDownload.exe" autostart>  [File is missing]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <runeip><"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup>  [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED]
    <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup>  [(Verified)KINGSOFT CORPORATION]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>  [(Verified)BEIJING RISING SCIENCE AND TECHNOLOGY CORPORATION LIMITED]
    <KASTask><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASTask.EXE">  [(Verified)KINGSOFT CORPORATION]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><c:\windows\system32\userinit.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><  ,kmon.dll>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><>  [N/A]
    <{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
    <mstimewd.dll><>  [N/A]
    <cliconfgzx.dll><>  [N/A]
    <ksuserfy.dll><>  [N/A]
    <adsntzt.dll><>  [N/A]
    <slbiopfs2.dll><>  [N/A]
    <dpvvoxmh.dll><>  [N/A]
    <msobjstl.dll><>  [N/A]
    <wmpuiqhx.dll><>  [N/A]
    <dispexcb.dll><>  [N/A]
    <tscfgwmijxsj.dll><>  [N/A]
    <imgutilhx2.dll><>  [N/A]
    <olecli32pt.dll><>  [N/A]
    <scrruncqsj.dll><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]

==================================
启动文件夹
[PPS]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\PPS.lnk --> C:\PROGRA~1\PPStream\PPStream.exe [PPStream Inc.]><N>
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[HWSuperPowerTablet / HWSuperPowerTablet][Running/Auto Start]
  <C:\WINDOWS\system32\JWPEN.exe><HanWang>
[Kingsoft Internet Security Common Service / KISSvc][Running/Auto Start]
  <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
  <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
  <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>

==================================
驱动程序
[4f2698e489d3abf1 / 4f2698e489d3abf1][Stopped/Manual Start]
  <\??\C:\4f2698e489d3abf1.dat><N/A>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde][Stopped/Disabled]
  <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[apcdli / apcdli][Stopped/Auto Start]
  <\??\C:\Program Files\Microsoft Office\SYSTEM\apcdli.sys><N/A>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[atiide / atiide][Stopped/Disabled]
  <\SystemRoot\system32\DRIVERS\atiide.sys><ATI Technologies Inc.>
[cb1e94f0b8696d31 / cb1e94f0b8696d31][Stopped/Manual Start]
  <\??\C:\cb1e94f0b8696d31.dat><N/A>
[CmdIde / CmdIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HiddFldy / HiddFldy][Stopped/Auto Start]
  <\??\C:\WINDOWS\system32\d32dx9.sys><N/A>
[Hy Pen / hypen][Running/Boot Start]
  <\SystemRoot\System32\Drivers\hypen.sys><N/A>
[KAVBase / KAVBase][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
[KAVBootC / KAVBootC][Running/Boot Start]
  <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
[KAVSafe / KAVSafe][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
[KNetWch / KNetWch][Running/System Start]
  <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
[KWatch3 / KWatch3][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[msiffei / msiffei][Stopped/Manual Start]
  <System32\Drivers\msiffei.sys><N/A>
[mv61xx / mv61xx][Stopped/Disabled]
  <\SystemRoot\system32\DRIVERS\mv61xx.sys><Marvell Semiconductor, Inc.>
[ntptdb / ntptdb][Running/Auto Start]
  <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
[nv / nv][Stopped/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver / rtl8029][Running/Manual Start]
  <system32\DRIVERS\RTL8029.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[sjmcmlnka / sjmcmlnkap][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\sjmcmlnkap.sys><>
[VIA AGP Filter / viaagp1][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[ATSpy / ATSpy][Running/Manual Start]
  <1060 - 指定的服务并未以已安装的服务存在。
><N/A>

==================================
浏览器加载项
[QQCycloneHelper Class]
  {00000000-12C9-4305-82F9-43058F20E8D2} <D:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[InceHelper Class]
  {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll, >
[卡卡上网安全助手]
  {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\WINDOWS\system32\UrlFilter.dll, Beijing Rising Technology Co., Ltd.>
[kingsoft browser shield]
  {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
[IEBuddyExtControl Class]
  {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
[QQCycloneHelper Class]
  {00000000-12C9-4305-82F9-43058F20E8D2} <D:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[IEBuddyExtControl Class]
  {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, Kingsoft Corporation>
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[InceHelper Class]
  {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll, >
[卡卡上网安全助手]
  {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} <C:\WINDOWS\system32\UrlFilter.dll, Beijing Rising Technology Co., Ltd.>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\Flash.OCX, Adobe Systems, Inc.>
[kingsoft browser shield]
  {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, Kingsoft Corporation>
[&使用超级旋风下载]
  <D:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
  <D:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>

==================================
正在运行的进程
[PID: 436 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 544 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4175]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 588 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 600 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 752 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4176]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2512]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2522]
[PID: 764 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 880 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 948 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1004 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4176]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2512]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2522]
    [C:\WINDOWS\system32\ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4175]
[PID: 1040 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1080 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1408 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [C:\WINDOWS\system32\syswindrv.dll]  [, 3, 3, 5, 0]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
[PID: 1508 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1756 / SYSTEM][C:\WINDOWS\system32\JWPEN.exe]  [HanWang, 2, 0, 0, 0]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
[PID: 1792 / Administrator][C:\Program Files\Rising\AntiSpyware\rstray.exe]  [Beijing Rising Technology Co., Ltd., 21.0.0.14]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\Program Files\Rising\AntiSpyware\rsmginfo.dll]  [Beijing Rising Technology Co., Ltd., 21, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
    [C:\Program Files\Rising\AntiSpyware\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Rising\AntiSpyware\ComServ.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.29]
    [C:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.4]
    [C:\Program Files\Rising\AntiSpyware\rscommon.dll]  [Beijing Rising Technology Co., Ltd., 20.0.1.0]
    [C:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.20]
    [C:\Program Files\Rising\AntiSpyware\pngdll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [C:\Program Files\Rising\AntiSpyware\runiep.dll]  [Beijing Rising Technology Co., Ltd., 6.0.0.30]
[PID: 1880 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 804 / Administrator][C:\Program Files\PPStream\PPStream.exe]  [PPStream Inc., 2, 2, 34, 1405]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.20]
    [C:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.4]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\PROGRA~1\PPStream\POWERP~1.DLL]  [PPStream Inc., 2,2,58,5951]
    [C:\PROGRA~1\PPStream\PSNetwork.dll]  [PPStream Inc., 1, 1, 0, 2568]
    [C:\Program Files\PPStream\fds.dll]  [PPStream Inc., 1, 0, 0, 70]
    [C:\PROGRA~1\PPStream\POWERL~1.OCX]  [PPStream Inc., 3, 0, 0, 1008]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
[PID: 2568 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.20]
    [C:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.4]
[PID: 3728 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.20]
    [C:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.4]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [D:\Program Files\Tencent\QQDownload\QQIEHelper01.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll]  [, 3, 5, 0, 0]
    [C:\WINDOWS\system32\UrlFilter.dll]  [Beijing Rising Technology Co., Ltd., 6, 0, 0, 13]
    [C:\Program Files\Rising\AntiSpyware\UrlRule.dll]  [Beijing Rising Technology Co., Ltd., 1.0.0.11]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL]  [Kingsoft Corporation, 2008,04,15,2]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL]  [Kingsoft Corporation, 2008,06,24,415]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\SogouInput\ZipLib.dll]  [N/A, ]
[PID: 2732 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.20]
    [C:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.4]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [D:\Program Files\Tencent\QQDownload\QQIEHelper01.dll]  [腾讯公司, 1, 1, 0, 5]
    [C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2164.dll]  [, 3, 5, 0, 0]
    [C:\WINDOWS\system32\UrlFilter.dll]  [Beijing Rising Technology Co., Ltd., 6, 0, 0, 13]
    [C:\Program Files\Rising\AntiSpyware\UrlRule.dll]  [Beijing Rising Technology Co., Ltd., 1.0.0.11]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL]  [Kingsoft Corporation, 2008,04,15,2]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll]  [Kingsoft Corporation, 2008,07,15,467]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL]  [Kingsoft Corporation, 2008,06,24,415]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KANTray.dll]  [Kingsoft Corporation, 2008,06,24,415]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVAFish.DLL]  [Kingsoft Corporation, 2008,06,24,415]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\Flash.OCX]  [Adobe Systems, Inc., 9,0,115,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\StormII\Codec\VSFilter.dll]  [Gabest, 1, 0, 1, 3]
    [C:\Program Files\StormII\Codec\PmpSplt.ax]  [cooleyes, 1, 0, 0, 8]
    [C:\Program Files\StormII\Codec\RadGtSplitter.ax]  [Gabest, 1, 0, 0, 0]
    [C:\Program Files\StormII\Codec\AviSplitter.ax]  [Gabest, 1, 0, 0, 7]
    [C:\Program Files\StormII\Codec\MpaSplitter.ax]  [Gabest, 1, 0, 0, 1]
    [C:\Program Files\StormII\codec\FLVSplitter.ax]  [Gabest, 1, 0, 0, 1]
    [C:\Program Files\StormII\Codec\MP4Splitter.ax]  [Gabest, 1, 0, 0, 2]
    [C:\Program Files\StormII\Codec\RMSplt.ax]  [Gabest, 1, 0, 1, 1]
    [C:\WINDOWS\system32\ffdshow.ax]  [, 1.0.2.2028]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 3808 / Administrator][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\WINDOWS\system32\kmon.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\Program Files\Rising\AntiSpyware\comx3.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.20]
    [C:\Program Files\Rising\AntiSpyware\Syslay.dll]  [Beijing Rising Technology Co., Ltd., 21.0.0.4]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 3248 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.681\SREngLdr.EXE]  [Smallfrogs Studio, 2.6.11.992]
[PID: 3192 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.681\SRE9b4eb966.EXE]  [Smallfrogs Studio, 2.6.11.992]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KMailOEBand.DLL]  [Kingsoft Corporation, 2008,04,02,5]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 3, 0]
    [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.681\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1       localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 544, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1756, C:\WINDOWS\SYSTEM32\JWPEN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3808, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3248, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.681\SRENGLDR.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================

TOP

怎么清楚木马群???是在我的电脑里找出来?一个一个删除?

TOP

下载删除工具(无敌删除器)
(DelayDelFile.rar)或参考http://bbs.duba.net/thread-21914617-1-1.html
说明:解压并打开DelayDelFile,复制以下待删除文件列表-->粘贴进(Ctrl+V)第一个空白框中-->按"添加"-->点击"删除"按钮
,再把该工具删除时备份的_Backup_文件夹打包传上来


请使用这个工具按照七楼操作
我的洞穴

耗子的杀毒空间
(空间里提供杀毒,修复工具 学习资料,以及其他系统工具)

★★★每周QQ表情和头像推荐★★★(11月3日~11月9日)
看帖必回,是一种美德
金山样本收集组1群号:51121013(求助人员禁止加入)开放时间:周一到周五(节假日除外)
互联网的力量是无穷大的,毒霸现在把大家联成一线,让大家都成为反病毒的一线主体

TOP

这些文件找不到啊!!!怎么清除!!!??

由于不熟悉金山的日志
只建议清除木马群的DLL
   [vidc.ffds] [已启用]           <ff_vfw.dll>
        文件路径: C:\WINDOWS\system32\ff_vfw.dll [服务器忙]
        [vidc.xivd] [已启用]           <C:\Program Files\StormII\codec\xvidvfw.dll>
        文件路径: C:\Program Files\StormII\codec\xvidvfw.dll [服务器忙]
        [vidc.tscc] [已启用]           <C:\WINDOWS\system32\tsccvid.dll>
        文件路径: C:\WINDOWS\system32\tsccvid.dll [服务器忙]
        [vidc.VP60] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP61] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP62] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP6F] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.FLV4] [已启用]           <C:\WINDOWS\system32\vp6vfw.dll>
        文件路径: C:\WINDOWS\system32\vp6vfw.dll [服务器忙]
        [vidc.VP70] [已启用]           <C:\WINDOWS\system32\vp7vfw.dll>
        文件路径: C:\WINDOWS\system32\vp7vfw.dll [服务器忙]
        [VIDC.FPS1] [已启用]           <frapsvid.dll>
        文件路径: C:\WINDOWS\system32\frapsvid.dll [服务器忙]
        [VIDC.VMnc] [已启用]           <vmnc.dll>
        文件路径: C:\WINDOWS\system32\vmnc.dll [服务器忙]
        [vidc.aasc] [已启用]           <aasc32.dll>
        文件路径: C:\WINDOWS\system32\aasc32.dll [服务器忙]
        [vidc.aas4] [已启用]           <aasc32.dll>
        文件路径: C:\WINDOWS\system32\aasc32.dll [服务器忙]
        [vidc.UCDO] [已启用]           <clrviddd.dll>
        文件路径: C:\WINDOWS\system32\clrviddd.dll [服务器忙]
        [vidc.LEAD] [已启用]           <LCODCCMP.DLL>
        文件路径: C:\WINDOWS\system32\LCODCCMP.DLL [服务器忙]
        [vidc.avrn] [已启用]           <avidavicodec.dll>
        文件路径: C:\WINDOWS\system32\avidavicodec.dll [服务器忙]
        [vidc.advj] [已启用]           <avidavicodec.dll>
        文件路径: C:\WINDOWS\system32\avidavicodec.dll [服务器忙]
        [vidc.asv1] [已启用]           <asusasv1.dll>
        文件路径: C:\WINDOWS\system32\asusasv1.dll [服务器忙]
        [vidc.asv2] [已启用]           <asusasv2.dll>
        文件路径: C:\WINDOWS\system32\asusasv2.dll [服务器忙]
        [vidc.asvx] [已启用]           <asusasv2.dll>
        文件路径: C:\WINDOWS\system32\asusasv2.dll [服务器忙]
        [vidc.vdom] [已启用]           <vdowave.drv>
        文件路径: C:\WINDOWS\system32\vdowave.drv [服务器忙]
        [vidc.I263] [已启用]           <i263_32.drv>
        文件路径: C:\WINDOWS\system32\i263_32.drv [服务器忙]
        [vidc.VCR2] [已启用]           <ativcr2.dll>
        文件路径: C:\WINDOWS\system32\ativcr2.dll [服务器忙]
        [vidc.lsvx] [已启用]           <lsvxdec.dll>
        文件路径: C:\WINDOWS\system32\lsvxdec.dll [服务器忙]