金山毒霸2009官方下载金山清理专家官方下载金山网盾官方下载金山急救箱官方下载
返回列表 回复 发帖

[求助] 紧急! 新型针对QQ和userinit病毒!!

首先 我打开金山清理专家 发现一个恶意软件(我电脑英文的 里面的中文是问号) 是Troj?Q???8.0  描述那里提到了QQ和userinit  删除,重启 开机抢杀技术把QQ目录下的QQ.exe和cheak_hook.dll 然后打开清理专家 发现异常的userinit 修复(清除) 我重装了QQ在同样目录 重启    打开清理专家 又发现Troj?Q???8.0!!!   然后就是重复上面的事情

怎么办啊啊!!   360没扫出任何东西 WINDOWS清理助手也没有  
前提是我QQ是www.qq.com(官网)下载的 不可能有病毒吧  请各位高手赶紧汇报此事情!!
另外cheak_hook.dll以前在QQ目录下没有的
提供一下杀软的日志
同时提供病毒详细信息:病毒路径+病毒文件名称
下载sreng:(点击下载sreng)

解压sreng2.zip-->打开SREngLdr.EXE-->勾选  智能扫描-->扫描-->保存报告
   
保存到桌面
将 SREngLOG.log 中内容完整的复制粘贴到论坛上来(快捷提示:ctrl+a全选,ctrl+c复制,ctrl+v粘贴),不要修改
如无法运行,请重命名文件夹名和文件名,如abc.exe/abc.com/abc.bat/abc.scr/abc.pif等
注意:扫描前请尽量关闭QQ、游戏、下载工具、媒体播放器等应用程序。

1、描述症状、杀软对病毒处理结果,提供病毒文件名和路径。
2、提供清理专家报告或者sreng报告。
3、可疑程序用压缩包 形式上报病毒样本上报区
http://bbs.duba.net/forum-3252-1.html
网上查到的:
华夏黑客联盟论坛 -> →『原创软件区』 -> 爱Q大盗 8.0V2(VIP版) 正式发布


木马运行后...
将会在C盘建立个自动运行文件

autorun.inf
里面有
SpiderNt.exe
rundll32.exe

然后会把QQ给替换掉
QQ目录下会增加这三个文件
QQ.exe
cheak_hook.dll
QQ.exe 
[ 本帖最后由 byxxdrls 于 2008-11-8 09:26 编辑 ]
可是我的C盘没有SpiderNt.exe
rundll32.exe 和 Autorun.inf啊   而且抢杀技术说他是Spyware
byxxdrls说清除点好吗? 他有什么症状啊 会盗Q号吗
http://203.208.39.99/search?q=cache:ZEF_oYbWfEMJ:www.hxhack.com/bbs/simple/index.php%3Ft178752_4.html+cheak_hook.dll&hl=zh-CN&ct=clnk&cd=5&gl=cn&st_usg=ALhdy29iAN-C9ul1hAH7GNwoIsvEZ8XOuA我是搜索到这个网页的。这是8月份的时候的事了,你中的可能是新版本。应该是盗QQ密码的吧。你自己看看吧。

要清除此毒,你按照2楼的做吧,或者把QQ目录中的两个病毒文件传上来。
楼主请上传个自己的系统的SRENG日志来看看
C盘没有NT开头的exe程序 包括WINDOWS和system32(里面有 但是我知道是系统的)
byxxdrls我怎么上传啊 一开机就被抢杀了...
我今天也出现了相同的情况... 是突然出现的, 之前毒霸没有找到任何病毒, 实时防毒什么的都是开的, 进安全模式杀毒也是没有结果. C盘里没有autorun.inf文件, 一切和正常开机差不多...
  1. 2008-11-08,13:00:28

  2. System Repair Engineer 2.7.0.1210
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

  5. Follow item(s) have been selected:
  6.     All Boot Items (Including Registry, Startup Folders, Services and so on)
  7.     Browser Add-ons
  8.     Running Processes (Including process model information)
  9.     File Associations
  10.     Winsock Provider
  11.     Autorun.Inf
  12.     HOSTS File
  13.     Process Privileges Scan
  14.     Scheduled Tasks
  15.     API HOOK
  16.     Hidden Process


  17. Boot Items
  18. Registry
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  20.     <CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  21. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  22.     <run><>  [N/A]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  24.     <KavStart><"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVStart.exe" -startup>  [(Verified)"Zhuhai  Kingsoft Software Co.,Ltd"]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  26.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  27.     <Userinit><c:\windows\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  28.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  29. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  30.     <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Publisher]
  31. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  32.     <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
  33.     <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
  34.     <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
  35.     <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
  37.     <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
  39.     <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
  41.     <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
  43.     <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
  45.     <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
  47.     <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
  49.     <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
  51.     <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
  53.     <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
  55.     <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Publisher]
  56.     <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Publisher]
  57. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
  58.     <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe>  [Microsoft Corporation]
  59. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  60.     <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
  61. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  62.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
  63. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
  64.    
  65. <RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
  66. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  67.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
  68. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  69.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  70. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  71.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
  72. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  73.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  74. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}]
  75.     <Internet Explorer><%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf>  [File is missing]
  76. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  77.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  78. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  79.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
  80. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  81.     <Address Book 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
  82. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  83.     <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
  84. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  85.     <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]
  86. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  87.     <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install>  [Microsoft Corporation]
  88. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  89.     <360Safetray><; D:\360safe\safemon\360Tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]

  90. ==================================
  91. Startup Folders
  92. [Unwired Launchpad]
  93.   <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Unwired Launchpad.lnk --> C:\PROGRA~1\Unwired\UwSCT.exe [Unwired Australia Pty Limited]><N>

  94. ==================================
  95. Services
  96. [.NET Runtime Optimization Service v2.0.50727_X86 / clr_optimization_v2.0.50727_32][Stopped/Auto Start]
  97.   <C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe><(File is missing)>
  98. [Kingsoft Internet Security Common Service / KISSvc][Running/Auto Start]
  99.   <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE><Kingsoft Corporation>
  100. [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
  101.   <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE"><Kingsoft Corporation>
  102. [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
  103.   <"C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE"><Kingsoft Corporation>

  104. ==================================
  105. Drivers
  106. [360AntiArp / 360AntiArp][Running/System Start]
  107.   <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
  108. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  109.   <system32\drivers\ac97intc.sys><Intel Corporation>
  110. [eamon / eamon][Running/Auto Start]
  111.   <system32\DRIVERS\eamon.sys><ESET>
  112. [easdrv / easdrv][Running/System Start]
  113.   <system32\DRIVERS\easdrv.sys><ESET>
  114. [epfwtdir / epfwtdir][Running/System Start]
  115.   <system32\DRIVERS\epfwtdir.sys><N/A>
  116. [KAVBase / KAVBase][Stopped/Manual Start]
  117.   <\??\C:\WINDOWS\system32\Drivers\KAVBase.sys><Kingsoft Corporation>
  118. [KAVBootC / KAVBootC][Running/Boot Start]
  119.   <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
  120. [KAVSafe / KAVSafe][Running/Auto Start]
  121.   <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
  122. [kmsinput / kmsinput][Stopped/Manual Start]
  123.   <\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
  124. [KNetWch / KNetWch][Running/System Start]
  125.   <\??\C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KNetWch.SYS><Kingsoft Corporation>
  126. [KWatch3 / KWatch3][Running/Auto Start]
  127.   <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
  128. [npkcrypt / npkcrypt][Stopped/Auto Start]
  129.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
  130. [nv / nv][Running/Manual Start]
  131.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  132. [DDK PACKET Protocol / Packet][Stopped/Manual Start]
  133.   <system32\DRIVERS\ProtoDrv.sys><360安全中心>
  134. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  135.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  136. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  137.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  138. [SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
  139.   <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心>
  140. [Secdrv / Secdrv][Stopped/Manual Start]
  141.   <system32\DRIVERS\secdrv.sys><N/A>
  142. [TCP/IP Protocol Driver / Tcpip][Running/System Start]
  143.   <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
  144. [TesSafe / TesSafe][Stopped/Manual Start]
  145.   <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>

  146. ==================================
  147. Browser Add-ons
  148. [QQCycloneHelper Class]
  149.   {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) 腾讯公司>
  150. [SafeMon Class]
  151.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\360safe\safemon\safemon.dll, (Signed) 360.CN>
  152. [kingsoft browser shield]
  153.   {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, (Signed) Kingsoft Corporation>
  154. [IEBuddyExtControl Class]
  155.   {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, (Signed) Kingsoft Corporation>
  156. [Windows Genuine Advantage Validation Tool]
  157.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, (Signed) Microsoft Corporation>
  158. [MUWebControl Class]
  159.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
  160. [Java Plug-in 1.6.0_07]
  161.   {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, N/A>
  162. []
  163.   {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
  164. [WebActivater Control]
  165.   {C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\system32\3DShowVM.ocx, QQ>
  166. [Java Plug-in 1.5.0_06]
  167.   {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, N/A>
  168. [Java Plug-in 1.6.0_05]
  169.   {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, N/A>
  170. [Java Plug-in 1.6.0_07]
  171.   {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, N/A>
  172. [Java Plug-in 1.6.0_07]
  173.   {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll, (Signed) Sun Microsystems, Inc.>
  174. [Shockwave Flash Object]
  175.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
  176. [PasswordEditCtrl Class]
  177.   {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, (Signed) 腾讯科技(深圳)有限公司>
  178. [QQCycloneHelper Class]
  179.   {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, (Signed) 腾讯公司>
  180. []
  181.   {00000AAA-A363-466E-BEF5-9BB68697AA7F} <, >
  182. []
  183.   {02478D38-C3F9-4EFB-9B51-7695ECA05670} <, >
  184. [Adobe PDF Reader Link Helper]
  185.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
  186. [Web Browser Applet Control]
  187.   {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
  188. []
  189.   {0A155D3C-68E2-4215-A47A-E800A446447A} <, >
  190. [IFlashGetNetscapeEx Class]
  191.   {116BA71C-8187-4F15-9A1F-C9D6289155D1} <C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlashGetBHO.dll, FlashGet>
  192. []
  193.   {220A105A-16EE-44C1-A4C8-AD76C709FC1D} <, >
  194. []
  195.   {2318C2B1-4965-11D4-9B18-009027A5CD4F} <, >
  196. [JetCarNetscape Class]
  197.   {2974c985-8151-4de5-b23c-b875f0a8522f} <C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlashGetBHO.dll, FlashGet>
  198. []
  199.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <, >
  200. []
  201.   {3AD14F0C-ED16-4E43-B6D8-661B03F6A1EF} <, >
  202. [IEBuddyExtControl Class]
  203.   {3AECD3C1-7085-4731-96DC-47B6CF7EF749} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddyExt.DLL, (Signed) Kingsoft Corporation>
  204. [Kingsoft Trojan Webshield]
  205.   {4E8A5278-C04E-4FE3-BF78-8A7CCD6EF333} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\IEBuddy.dll, (Signed) Kingsoft Corporation>
  206. []
  207.   {53707962-6F74-2D53-2644-206D7942484F} <, >
  208. [Shell Name Space]
  209.   {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
  210. [Windows Media Player]
  211.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
  212. [SSVHelper Class]
  213.   {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, N/A>
  214. []
  215.   {7E853D72-626A-48EC-A868-BA8D5E23E045} <, >
  216. [360SafeLive]
  217.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\360safe\live.dll, (Signed) 360.cn>
  218. [Microsoft Web Browser]
  219.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, (Signed) Microsoft Corporation>
  220. []
  221.   {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
  222. []
  223.   {9030D464-4C02-4ABF-8ECC-5164760863C6} <, >
  224. []
  225.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
  226. []
  227.   {94EDF7B4-4272-4AF3-8F8B-4E2F68E225B7} <, >
  228. []
  229.   {962EFB8E-2683-42D4-AC74-AAA4C759B9C6} <, >
  230. []
  231.   {A303AF11-721F-4185-B87B-5027CE6EE538} <, >
  232. []
  233.   {AA58ED58-01DD-4D91-8333-CF10577473F7} <, >
  234. [FlashGetBHO]
  235.   {B070D3E3-FEC0-47D9-8E8A-99D4EEB3D3B0} <C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlashGetBHO.dll, FlashGet>
  236. [SearchAssistantOC]
  237.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
  238. [SafeMon Class]
  239.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\360safe\safemon\safemon.dll, (Signed) 360.CN>
  240. [RDS.DataSpace]
  241.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, (Signed) Microsoft Corporation>
  242. []
  243.   {C95FE080-8F5D-11D2-A20B-00AA003C157A} <, >
  244. [AUDIO__MP3 Moniker Class]
  245.   {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
  246. [AUDIO__X_MS_WMA Moniker Class]
  247.   {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
  248. [Shockwave Flash Object]
  249.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
  250. []
  251.   {D82303B7-A754-4DCB-8AFC-8CF99435AACE} <, >
  252. [kingsoft browser shield]
  253.   {D963BE1A-6B35-47DB-B002-49FAE71D85CC} <C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KASBrowserShield.DLL, (Signed) Kingsoft Corporation>
  254. [PasswordEditCtrl Class]
  255.   {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, (Signed) 腾讯科技(深圳)有限公司>
  256. []
  257.   {EF99BD32-C1FB-11D2-892F-0090271D4F88} <, >
  258. []
  259.   {F19455F5-ADF4-4171-9111-3AF65819FE4B} <, >
  260. []
  261.   {FB5DA724-162B-11D3-8B9B-AA70B4B0B525} <, >
  262. []
  263.   {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
  264. [&Google Search]
  265.   <res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
  266. [E&xport to Microsoft Excel]
  267.   <res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>
  268. [使用快车(Flas&hGet)下载]
  269.   <D:\FlashGet Network\FlashGet\GetUrl.htm, N/A>
  270. [使用快车(Flash&Get)下载全部链接]
  271.   <D:\FlashGet Network\FlashGet\GetAllUrl.htm, N/A>
  272. [使用快车(FlashGet)下载该网页FLV]
  273.   <D:\FlashGet Network\FlashGet\FlvDetector.htm, N/A>
  274. [添加到QQ表情]
  275.   <D:\QQ\AddEmotion.htm, N/A>

  276. ==================================
  277. Running Processes
  278. [PID: 428 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  279. [PID: 476 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  280. [PID: 500 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  281.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  282. [PID: 544 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  283.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  284. [PID: 556 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  285.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  286. [PID: 708 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  287.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  288. [PID: 772 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  289.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  290. [PID: 852 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  291.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  292. [PID: 936 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  293.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  294. [PID: 1020 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  295.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  296. [PID: 1132 / SYSTEM][C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KPfwSvc.EXE]  [Kingsoft Corporation, 2008,10,21,649]
  297.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
  298.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
  299.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
  300.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
  301.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
  302.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  303. [PID: 1148 / SYSTEM][C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KWatch.EXE]  [Kingsoft Corporation, 2008,10,21,649]
  304.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
  305.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
  306.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
  307.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
  308.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  309.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
  310.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KARetr.DLL]  [Kingsoft Corporation, 1, 0, 0, 1]
  311.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVEvent.DLL]  [Kingsoft Corporation, 2008,04,02,5]
  312.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVIPC2.DLL]  [Kingsoft Corporation, 2008,07,15,469]
  313.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVDevC.dll]  [Kingsoft Corporation, 2008,07,24,115]
  314. [PID: 1464 / su][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  315.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  316.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  317.     [D:\WinRAR\rarext.dll]  [N/A, ]
  318.     [D:\Unlocker\UnlockerCOM.dll]  [N/A, ]
  319.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
  320.     [C:\WINDOWS\system32\dfshim.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  321.     [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  322.     [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Shfusion.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  323.     [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Fusion.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  324.     [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\culture.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  325.     [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  326. [PID: 1608 / SYSTEM][C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.EXE]  [Kingsoft Corporation, 2008,04,02,5]
  327.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
  328.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
  329.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kis.dll]  [Kingsoft Corporation, 2008,04,22,364]
  330.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
  331.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
  332.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  333.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KISSvc.DLL]  [Kingsoft Corporation, 2008,04,02,5]
  334.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kspeedup.dll]  [Kingsoft Corporation, 2008,04,22,364]
  335.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\kavipc2.dll]  [Kingsoft Corporation, 2008,07,15,469]
  336.     [C:\Program Files\Kingsoft\Kingsoft Internet Security 2008\KAVRep.DLL]  [Kingsoft Corporation, 2008,04,30,183]
  337. [PID: 1700 / su][C:\WINDOWS\system32\ctfmon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  338.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  339. [PID: 1796 / su][C:\Program Files\Unwired\UwSCT.exe]  [Unwired Australia Pty Limited, 1.3.0]
  340.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  341. [PID: 460 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  342.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  343. [PID: 1704 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  344.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  345. [PID: 848 / su][D:\QQ\QQ.exe]  [TENCENT, 8,0,978,1833]
  346.     [D:\QQ\QQBaseClassInDll.dll]  [TENCENT, 8,0,978,1833]
  347.     [D:\QQ\QQHelperDll.dll]  [TENCENT, 8,0,978,1833]
  348.     [D:\QQ\BasicCtrlDll.dll]  [TENCENT, 8,0,978,1833]
  349.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  350.     [D:\QQ\QQAPI.dll]  [TENCENT, 8,0,978,1833]
  351.     [D:\QQ\LoginCtrl.dll]  [TENCENT, 8,0,978,1833]
  352.     [D:\QQ\LoginCtrlRes.dll]  [TENCENT, 8,0,978,1833]
  353.     [D:\QQ\QQRes.dll]  [TENCENT, 8,0,978,1833]
  354.     [D:\QQ\WizardCtrl.dll]  [TENCENT, 8,0,978,1833]
  355.     [D:\QQ\QQMainFrame.dll]  [TENCENT, 8,0,978,1833]
  356.     [D:\QQ\QQPlugin.dll]  [TENCENT, 8,0,978,1833]
  357.     [D:\QQ\UnReadMsgMgr.dll]  [TENCENT, 8,0,978,1833]
  358.     [D:\QQ\QQAllInOne.dll]  [TENCENT, 8,0,978,1833]
  359.     [D:\QQ\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
  360.     [D:\QQ\CameraDll.dll]  [TENCENT, 8,0,978,1833]
  361.     [D:\QQ\CQQApplication.dll]  [TENCENT, 8,0,978,1833]
  362.     [D:\QQ\FlashAvatarDll.dll]  [, 1, 0, 0, 1]
  363.     [D:\QQ\NewSkin.dll]  [TENCENT, 8,0,978,1833]
  364.     [D:\QQ\MailSummary.dll]  [TENCENT, 8,0,978,1833]
  365.     [D:\QQ\QQSpace.dll]  [TENCENT, 8,0,978,1833]
  366.     [C:\WINDOWS\system32\devenum.dll]  [, ]
  367.     [C:\WINDOWS\system32\msdmo.dll]  [, ]
  368.     [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
  369.     [D:\QQ\OEMApplication.dll]  [TENCENT, 8,0,978,1833]
  370.     [D:\QQ\QQAvatar.dll]  [TENCENT, 8,0,978,1833]
  371.     [D:\QQ\QQKnowledgeSearch.dll]  [TENCENT, 8,0,978,1833]
  372.     [D:\QQ\QQGroupMng.dll]  [TENCENT, 8,0,978,1833]
  373.     [D:\QQ\QQPet.dll]  [TENCENT, 8,0,978,1833]
  374.     [D:\QQ\QRingMng.dll]  [TENCENT, 8,0,978,1833]
  375.     [D:\QQ\QQSysMsgMng.dll]  [TENCENT, 8,0,978,1833]
  376.     [D:\QQ\UserDefinedHead.dll]  [TENCENT, 8,0,978,1833]
  377.     [D:\QQ\LongConnection.dll]  [TENCENT, 8,0,978,1833]
  378.     [D:\QQ\QQConfigPlugin.dll]  [TENCENT, 8,0,978,1833]
  379.     [D:\QQ\QQCustomFace.dll]  [TENCENT, 8,0,978,1833]
  380.     [D:\QQ\QQFileTransfer.dll]  [TENCENT, 8,0,978,1833]
  381.     [D:\QQ\PhoneAPI.dll]  [TENCENT, 8,0,978,1833]
  382.     [D:\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
  383.     [D:\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
  384.     [D:\QQ\BQQApplication.dll]  [TENCENT, 8,0,978,1833]
  385.     [D:\QQ\QQSettingCtrl.dll]  [TENCENT, ]
  386.     [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
  387.     [D:\QQ\CommercesMng.dll]  [TENCENT, 8,0,978,1833]
  388.     [D:\QQ\PersonalDesktop.dll]  [TENCENT, 8,0,978,1833]
  389.     [D:\QQ\QQSceneMng.dll]  [TENCENT, 8,0,978,1833]
  390.     [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  391.     [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
  392.     [D:\QQ\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 2, 1, 17]
  393.     [D:\QQ\ImageOle.dll]  [TENCENT, 8,0,978,1833]
  394.     [D:\QQ\QQMagicFace.dll]  [TENCENT, 8,0,978,1833]
  395.     [D:\QQ\QQLiveQMng.dll]  [TENCENT, 8,0,978,1833]
  396.     [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 3.5.0.0]
  397.     [D:\SogouInput\Plugin\SgImeWord.dll]  [Sogou.com Inc., 3.5.0.0]
  398.     [D:\QQ\GroupConnection.dll]  [TENCENT, 8,0,978,1833]
  399. [PID: 976 / su][D:\QQ\TXPlatform.exe]  [Tencent, 1, 5, 225, 0]
  400. [PID: 3448 / su][D:\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
  401. [PID: 3456 / su][D:\sreng2\SRE679b2568.EXE]  [Smallfrogs Studio, 2.7.0.1210]
  402.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll]  [Microsoft Corporation, 6.0 (xpsp.060825-0040)]
  403.     [D:\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

  404. ==================================
  405. File Associations
  406. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  407. .EXE  OK. ["%1" %*]
  408. .COM  OK. ["%1" %*]
  409. .PIF  OK. ["%1" %*]
  410. .REG  OK. [regedit.exe "%1"]
  411. .BAT  OK. ["%1" %*]
  412. .SCR  OK. ["%1" /S]
  413. .CHM  Error. ["hh.exe" %1]
  414. .HLP  Error. [winhlp32.exe %1]
  415. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  416. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  417. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  418. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  419. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  420. ==================================
  421. Winsock Provider
  422. N/A

  423. ==================================
  424. Autorun.Inf
  425. N/A

  426. ==================================
  427. HOSTS File
  428. 127.0.0.1       localhost

  429. ==================================
  430. Process Privileges Scan
  431. Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1796, C:\PROGRAM FILES\UNWIRED\UWSCT.EXE]
  432. Special Privileges Enabled: SeLoadDriverPrivilege [PID = 3448, D:\SRENG2\SRENGLDR.EXE]

  433. ==================================
  434. Scheduled Tasks
  435. [Disabled] 【请注意文明用语】 NetDetect.job
  436.         C:\Program Files\【请注意文明用语】\LiveUpdate\NDETECT.EXE

  437. ==================================
  438. API HOOK
  439. N/A

  440. ==================================
  441. Hidden Process
  442. N/A

  443. ==================================
复制代码
以上是sreng报告
英文版的,看得眼花。没看出什么名堂。
vistalong去哪了..帮我看看啊
就没有人来帮帮我啊   这东西就是清不掉
查看隐藏和系统文件
我的电脑---工具---文件夹选项--查看--
在“显示系统文件夹”“显示所有文件和文件夹”2个地方打上钩
这一项如果被病毒破坏 请用附件中的工具
打开我的电脑  然后 搜索 QQ.exe   、cheak_hook.dll 、SpiderNt.exe、
rundll32.exe这几个文件用压缩包上传

显示被隐藏的文件.rar (336 Bytes)


1、描述症状、杀软对病毒处理结果,提供病毒文件名和路径。
2、提供清理专家报告或者sreng报告。
3、可疑程序用压缩包 形式上报病毒样本上报区
http://bbs.duba.net/forum-3252-1.html
运行病毒后,写入文件的大致情况

5817        46:58.9        com.exe        1512        写入文件        C:\Documents and Settings\Administrator\Local Settings\Temp\E_4\krnln.fnr               
5839        46:59.0        com.exe        1512        写入文件        C:\Documents and Settings\Administrator\Local Settings\Temp\E_4\dp1.fne               
5843        46:59.0        com.exe        1512        写入文件        C:\Documents and Settings\Administrator\Local Settings\Temp\E_4\eAPI.fne               
5857        46:59.1        com.exe        1512        写入文件        C:\Documents and Settings\Administrator\Local Settings\Temp\E_4\shell.fne               
6927        46:59.8        com.exe        1512        写入文件        C:\PZAQ.ini               
6942        46:59.8        com.exe        1512        写入文件        C:\Recycled\desktop.ini               
6991        46:59.9        com.exe        1512        写入文件        C:\Recycled\iext5.fne               
7010        46:59.9        com.exe        1512        写入文件        C:\Recycled\shellEx.fne               
7022        46:59.9        com.exe        1512        写入文件        C:\Recycled\xplib.fne               
7034        46:59.9        com.exe        1512        写入文件        C:\Recycled\internet.fne               
7060        46:59.9        com.exe        1512        写入文件        C:\Recycled\krnln.fne               
7240        47:00.0        com.exe        1512        写入文件        C:\Recycled\eAPI.fne               
7291        47:00.0        com.exe        1512        写入文件        C:\Recycled\dp1.fne               
7941        47:00.3        com.exe        1512        写入文件        C:\autorun.inf\desktop.ini               
8038        47:00.5        com.exe        1512        写入文件        C:\autorun.inf\文件免疫.\AQ               
8111        47:00.7        com.exe        1512        写入文件        D:\autorun.inf\desktop.ini               
8131        47:00.7        com.exe        1512        写入文件        D:               
8165        47:00.8        com.exe        1512        写入文件        D:\autorun.inf\文件免疫.\AQ               
8221        47:00.9        com.exe        1512        写入文件        D:\Backup\桌面\QQ.exe                
8245        47:01.0        com.exe        1512        写入文件        D:\autorun.inf\SpiderNt.exe                
8284        47:01.0        com.exe        1512        写入文件        C:\Recycled\Recycledbk.exe                
8325        47:01.0        com.exe        1512        写入文件        C:\Recycled\Recycled.exe                
8336        47:01.0        com.exe        1512        写入文件        D:\Backup\桌面\cheak_hook.dll               
10059        47:01.6        com.exe        1512        写入文件        C:\Documents and Settings\All Users\桌面\腾讯QQ.lnk               
12638        47:02.9        Recycled.exe         1536        写入文件        D:\autorun.inf\rundll32.exe               
13293        47:03.2        com.exe        1512        写入文件        C:\Documents and Settings\Administrator\Local Settings\Temp\d1e0.tmp               
16227        47:04.6        Recycled.exe         1536        写入文件        C:\Recycled\Recycled.exe 
autorun.inf\和Recycled\这两个文件夹内的文件被隐藏了(即使隐藏的系统文件能看到,这些文件也看不到),得用冰刃才能看到,在DOS下也可以用
C:\Documents and Settings\Administrator\Local Settings\Temp\  里面什么也没有
以下文件和文件夹地址找不到(地址栏打进去说找不到):
C:\autorun.inf
D:\Backup\
D:\autorun.inf
C:\Recycled\
C:\PZAQ.ini
D:\autorun.inf\rundll32.exe

回复 17楼 的帖子

你用什么软件查到病毒写入时间?
返回列表