|
NND我要干死它
我的情况和楼主的一样,诺顿把我所有的.EXE文件全部都隔离了,这些文件都中了同一个病毒:W32.Fubalca.B
能不能恢复这些文件啊?求各位高人帮忙啊,急啊!!!以下是我的sreng扫描日记:
- 2007-04-25,09:10:09
- System Repair Engineer 2.4.12.806
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 启动项目
- 注册表
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
- <SiS Windows KeyHook><C:\WINDOWS\system32\keyhook.exe> [Silicon Integrated Systems Corporation]
- <vptray><C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe> [Symantec Corporation]
- <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
- <360Safetray><F:\360safe\safemon\360tray.exe> [奇虎网]
- <StormCodec_Helper><"F:\暴风影音\Storm Codec\StormSet.exe" /S /opti> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
- <Userinit><C:\WINDOWS\system32\Userinit.exe,> [(Verified)Microsoft Windows Publisher]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
- <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll> []
- ==================================
- 启动文件夹
- [eEye Windows Animated Cursor Patch Checker]
- <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\eEye Windows Animated Cursor Patch Checker.lnk --> C:\PROGRA~1\EEYEDI~1\WINDOW~1.ANI\ANIPAT~1.EXE [eEye Digital Security]><N>
- ==================================
- 服务
- [DefWatch / DefWatch][Running/Auto Start]
- <C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe><Symantec Corporation>
- [fhsqphm / fhsqphm][Running/Auto Start]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\COMMON~1\lhsqchm\lhsqchm.dll>< >
- [Google Updater Service / gusvc][Stopped/Manual Start]
- <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
- [TCP/IP Check / Hello Download][Stopped/Auto Start]
- <C:\Program Files\Common Files\System\wab32res.exe><N/A>
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [Symantec AntiVirus Client / Norton AntiVirus Server][Running/Auto Start]
- <C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe><Symantec Corporation>
- [Vsn vtic Service / vtic][Stopped/Auto Start]
- <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\bwoi\idvp.dll,Service><Microsoft Corporation>
- [ykueca / ykueca][Stopped/Auto Start]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\lkueca\lkueca.dll>< >
- ==================================
- 驱动程序
- [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
- <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
- [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
- <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
- [AliIde / AliIde][Stopped/Boot Start]
- <\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
- [CmdIde / CmdIde][Running/Boot Start]
- <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
- [Njdatas General Purpose USB Driver (drusb.sys) / DRUSB][Stopped/Auto Start]
- <System32\Drivers\drusb.sys><Nanjing Datas System Software Co. Ltd.>
- [MegaIDE / MegaIDE][Running/Boot Start]
- <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
- [NAVAP / NAVAP][Running/Manual Start]
- <\??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys><Symantec Corporation>
- [NAVAPEL / NAVAPEL][Running/Auto Start]
- <\??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS><Symantec Corporation>
- [NAVENG / NAVENG][Running/Manual Start]
- <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070423.019\NAVENG.sys><Symantec Corporation>
- [NAVEX15 / NAVEX15][Running/Manual Start]
- <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070423.019\NAVEX15.sys><Symantec Corporation>
- [npkcrypt / npkcrypt][Running/Auto Start]
- <\??\F:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
- [npkycryp / npkycryp][Stopped/Manual Start]
- <\??\F:\QQ\npkycryp.sys><N/A>
- [nv / nv][Stopped/Manual Start]
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
- [Logitech QuickCam Express(PID_0920) / PID_0920][Stopped/Manual Start]
- <system32\DRIVERS\LV532AV.SYS><N/A>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [PxHelp20 / PxHelp20][Running/Boot Start]
- <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
- [Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver / RTL8023][Running/Manual Start]
- <system32\DRIVERS\Rtlnic51.sys><Realtek Semiconductor Corporation>
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
- <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys><N/A>
- [Sentinel / Sentinel][Running/Auto Start]
- <\SystemRoot\System32\Drivers\SENTINEL.SYS><>
- [SiS315 / SiS315][Running/Manual Start]
- <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
- [SiS AGP Filter / SISAGP][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation>
- [SiSide / SiSide][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\siside.sys><Silicon Integrated Systems Corp.>
- [SiSkp / SiSkp][Running/System Start]
- <system32\drivers\srvkp.sys><Silicon Integrated Systems Corporation>
- [Add Performance Filter Driver / sisperf][Running/Boot Start]
- <\SystemRoot\system32\drivers\sisperf.sys><Silicon Integrated Systems Corp.>
- [sptd / sptd][Running/Boot Start]
- <\SystemRoot\System32\Drivers\sptd.sys><N/A>
- [SymEvent / SymEvent][Running/Manual Start]
- <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
- [ViaIde / ViaIde][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
- <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
- ==================================
- 浏览器加载项
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <F:\迅雷\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
- [NavigatMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <F:\360safe\safemon\safemon.dll, >
- [启动迅雷5]
- {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <F:\迅雷\Thunder.exe, N/A>
- [讯通视频语音聊天]
- {97C0CDFA-970D-4222-ADDE-6718E89E887C} <http://www.bdsystem.com/, N/A>
- [Messenger]
- {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
- [BitComet工具栏]
- {3F1ABCDB-A875-46c1-8345-B72A4567E486} <F:\BitComet\BitCometBar\BitCometBar0.6.dll, >
- [MMCPlayer Class]
- {05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
- [AddSHCARoot Control]
- {098A3F72-3110-4004-B954-2F9DC44934B4} <C:\WINDOWS\DOWNLO~1\ADDCAR~1.OCX, SHECA>
- [PhotoDraw Class]
- {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <C:\WINDOWS\system32\QQPhotoDraw.dll, TENCENT>
- [Office Update Installation Engine]
- {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} <C:\WINDOWS\opuc.dll, Microsoft Corporation>
- [CPasswordEditCtrl Object]
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
- [MMCPlayer Class]
- {05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
- [AddSHCARoot Control]
- {098A3F72-3110-4004-B954-2F9DC44934B4} <C:\WINDOWS\DOWNLO~1\ADDCAR~1.OCX, SHECA>
- [PeerDraw Class]
- {10072CEC-8CC1-11D1-986E-00A0C955B42E} <C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll, Microsoft Corporation>
- [Windows Genuine Advantage Validation Tool]
- {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
- [Windows Media Player]
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
- [PhotoDraw Class]
- {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <C:\WINDOWS\system32\QQPhotoDraw.dll, TENCENT>
- [Recorder Control]
- {2423AB16-9F42-457B-A337-FE3B11964DB0} <F:\蓝天插件\BLUESK~1\recorder.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [HTML Document]
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
- [DHTML Edit Control Safe for Scripting for IE5]
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
- [vqfs]
- {2E5A0909-3B10-4504-89C5-C4662CA8D1B8} <C:\PROGRA~1\bwoi\fasm.dll, N/A>
- [BlueskyVideo Control]
- {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} <F:\蓝天插件\BLUESK~1\v2.ocx, 蓝天工作室(http://www.bluesky.cn)>
- [Share Control]
- {3072B1F1-0C4D-4E76-A7C6-FBAF129DBCC9} <F:\蓝天插件\BLUESK~1\share.ocx, http://www.bluesky.cn>
- [BitComet工具栏]
- {3F1ABCDB-A875-46C1-8345-B72A4567E486} <F:\BitComet\BitCometBar\BitCometBar0.6.dll, >
- [Microsoft Office Control]
- {4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} <C:\PROGRA~1\MICROS~2\OFFICE11\AUTHZAX.DLL, Microsoft Corporation>
- [Shell Name Space]
- {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
- [Windows Media Player]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
- [BDC Control]
- {7253A666-8D4A-11D7-A4DC-00E04C504779} <F:\PROGRA~1\BDC\Bdc.ocx, BLUE>
- [Videohelp Control]
- {75B75D86-D88B-4BEA-BC59-BFD9D7300518} <F:\蓝天插件\BLUESK~1\VIDEOH~1.OCX, Bluesky Studio(http://www.bluesky.cn)>
- [Microsoft Web 浏览器]
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <F:\迅雷\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
- [Blueskyvoice Control]
- {991481A7-4669-4E15-8C24-100404E1F5CB} <F:\蓝天插件\BLUESK~1\BLUESK~1.OCX, 蓝天工作室(http://www.bluesky.cn)>
- [Display Control]
- {A1D97DB3-E564-4743-B2E7-6F5182CBF406} <F:\蓝天插件\BLUESK~1\display.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [Microsoft Scriptlet Component]
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
- [SearchAssistantOC]
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
- [NavigatMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <F:\360safe\safemon\safemon.dll, >
- [RDS.DataSpace]
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\MSADC\msadco.dll, Microsoft Corporation>
- [Play Control]
- {CC20DDA1-9A21-4DEC-B5BE-E61E0351FCA9} <F:\蓝天插件\BLUESK~1\play.ocx, Bluesky Studio (http://www.bluesky.cn)>
- [AUDIO__X_MS_WMA Moniker Class]
- {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
- [RealPlayer G2 Control]
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
- [CPasswordEditCtrl Object]
- {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
- [&使用迅雷下载]
- <F:\迅雷\Program\GetUrl.htm, N/A>
- [&使用迅雷下载全部链接]
- <F:\迅雷\Program\GetAllUrl.htm, N/A>
- [上传到QQ网络硬盘]
- <F:\QQ\AddToNetDisk.htm, N/A>
- [导出到 Microsoft Office Excel(&X)]
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
- ==================================
- 正在运行的进程
- [PID: 492][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 544][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 568][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\NavLogon.dll] [N/A, ]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1444][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [F:\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [F:\QQ\qdshm.dll] [, 1, 0, 101, 20]
- [F:\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
- [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] [Symantec Corporation, 8.1.0.821]
- [F:\迅雷\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
- [PID: 1656][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.14]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [PID: 1688][C:\WINDOWS\system32\keyhook.exe] [Silicon Integrated Systems Corporation, 0.0.0.3571]
- [C:\WINDOWS\system32\SiSApCom.dll] [Silicon Integrated Systems Corporation, 0.0.0.3571]
- [C:\WINDOWS\system32\SiSBase.dll] [Silicon Integrated Systems Corporation, 6.14.10.3571]
- [C:\WINDOWS\system32\InstFunc.dll] [Silicon Integrated Systems Corporation, 6.14.10.3571]
- [C:\WINDOWS\system32\SiSParse.dll] [Silicon Integrated Systems Corporation, 6.14.10.3571]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [PID: 1696][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe] [Symantec Corporation, 8.1.0.821]
- [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 8.1.0.821]
- [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVNTUTL.DLL] [Symantec/Peter Norton Group, 1, 0, 0, 1]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 8.1.0.821]
- [PID: 1728][F:\360safe\safemon\360tray.exe] [奇虎网, 3, 3, 0, 1004]
- [F:\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
- [F:\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 2, 0, 1001]
- [F:\360safe\AntiAdwa.dll] [360Safe.com, 3, 3, 0, 1004]
- [F:\360safe\live.dll] [360safe.COM, 1, 0, 0, 1012]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [PID: 1672][C:\Documents and Settings\meng\桌面\Antiarp.exe] [N/A, ]
- [F:\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [PID: 2744][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [F:\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [F:\迅雷\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
- [c:\progra~1\lkueca\lkunqob.dat] [ , 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [F:\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [c:\progra~1\lkueca\lkuygd.dll] [ , 5, 7, 0, 2]
- [PID: 3620][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [F:\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- [F:\迅雷\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.3100 (xpsp_sp2_gdr.070309-0025)]
- [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [F:\暴风影音\Storm Codec\Codecs\VSFilter.dll] [Gabest, 1, 0, 1, 3]
- [F:\迅雷\Components\VPShell\RealMediaSplitter.ax] [Gabest, 1, 0, 1, 0]
- [C:\WINDOWS\system32\ffdshow.ax] [, 1.0.2.2028]
- [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [PID: 2216][C:\Documents and Settings\meng\桌面\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
- [F:\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
- [c:\progra~1\lkueca\lkuewy.nls] [, 5, 6, 0, 2]
- [c:\progra~1\lkueca\lkudql.nls] [ , 5, 8, 0, 2]
- [c:\progra~1\common~1\lhsqchm\fjpnkgj.nls] [, 2, 6, 0, 2]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- API HOOK
- 入口点错误:CreateProcessA (危险等级: 一般, 被下面模块所HOOK: F:\360safe\safemon\safemon.dll)
- 入口点错误:CreateProcessW (危险等级: 一般, 被下面模块所HOOK: F:\360safe\safemon\safemon.dll)
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码 |
|