国光帮帮忙 大哥,大哥们帮帮忙啊

大哥们帮帮忙啊 - 故障解答 - 电脑教程网

大哥们帮帮忙啊

日期:2007-03-30   荐:
.Cbz664 网吧记费服务器.经常弹出网业.用木马杀客和超级兔子都查过了.什么都没有.不定时的弹出两个网页
一个是http://www.7yin.com/ 另一个是 http://www.34pp.com/ 自动保存到收藏夹每次重起都会在桌面
上生成两个快捷方式怎么删也删不掉啊
Logfile of HijackThis v1.99.1
Scan saved at 20:50:00, on 2006-9-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Octopus\Server.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\new\桌面\17aqkkan\空空的按钮突破专家\空空的按钮突破专家.exe
D:\Octopus\rzxsurename.exe
C:\Program Files\木马杀客\mmsk.exe
F:\HLSW中文版\HLSW中文版\HLSW1.0.0.15.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\alexa.exe dngz.net
F:\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\QQ2005\QQIEHelper.dll
O4 - HKLM\..\Run: [78vodreg] ; C:\WINDOWS\78vod.exe
O4 - HKLM\..\Run: [ssServ] D:\Octopus\Server.exe
O4 - HKLM\..\RunServices: [78vodreg] ; C:\WINDOWS\78vod.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe (www.dngz.net)版权所有
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) www.dngz.net
O23 - Service: RzxSevce - 深圳任子行网络技术有限公司 - d:\Program Files\rzx\Net110\RzxSevce.exe
O23 - Service: System Application - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe (file missing)
[ 本帖最后由 yaokaku 于 2006-9-15 21:05 编辑 ]

会不会和下面这个有关系
O4 - HKLM\..\Run: [78vodreg] ; C:\WINDOWS\78vod.exe
修复下面,以及后面带  file missing
O23 - Service: System Application - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe (file missing)
下面这个好象是个广告
C:\WINDOWS\system32\alexa.exe

重起后还是弹出一个网页www.78du.com  我快要疯了
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm ;
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) ;
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: RzxSevce - 深圳任子行网络技术有限公司 - d:\Program Files\rzx\Net110\RzxSevce.exe

C:\WINDOWS\78vod.exe  删除这个文件
还不行就用黄山IE 或其他上网修复软件

用System Repair Engineer 2.0.21.505 扫描个日志看看

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
这个服务不知是什么,如不熟悉,最好禁用并删除其中的rpcapd.exe和rpcapd.ini

呵呵~~~你好彩~~中了跟我一样的病毒!!下载器变种!!我花了几天才删除掉!
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
问题在这里!!参考下面地址
http://www.fcbu.com/bbs/thread-100921-1-6.html
记得删除后要重新启动电脑才行!!

我找不到Realplayer.exe  的系统进程

Logfile of HijackThis v1.99.1
Scan saved at 19:15:26, on 2006-9-16
Platform: Windows XP SP2 (WinNT 5.01.2600) dngz.net
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\new\桌面\17aqkkan\空空的按钮突破专家\空空的按钮突破专家.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\HLSW中文版\HLSW中文版\HLSW1.0.0.15.exe
D:\Octopus\Server.exe
D:\Octopus\rzxsurename.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\木马杀客\mmsk.exe
F:\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\QQ2005\QQIEHelper.dll
O4 - HKLM\..\Run: [ssServ] D:\Octopus\Server.exe
O4 - HKLM\..\Run: [C-Media Mixer] ; Mixer.exe /startup
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 欢迎来到(www.dngz.net)
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [91cast] ;
O4 - HKCU\..\Run: [boot-hf] ; c:\windows\BOOT-hf.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe 本文来自 www.dngz.net
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: RzxSevce - 深圳任子行网络技术有限公司 - d:\Program Files\rzx\Net110\RzxSevce.exe

O4 - HKCU\..\Run: [91cast] ;
就是这个了
取消启动后,搜索91cast相关并删除

用System Repair Engineer 2.0.21.505扫描结果
2006-09-16,19:35:39
System Repair Engineer 2.0.21.505 (2.0 RC 2) ,
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程?樾畔ⅲ?br>     文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <91cast><; >  []
    <boot-hf><; c:\windows\BOOT-hf.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <ssServ><D:\Octopus\Server.exe>  [吉胜科技]
    <C-Media Mixer><; Mixer.exe /startup>  [C-Media Electronic Inc. (www.cmedia.com.tw)]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation] dngz.net
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\Windows\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]


==================================
启动文件夹
服务
[RzxSevce / RzxSevce]
  <d:\Program Files\rzx\Net110\RzxSevce.exe><深圳任子行网络技术有限公司>
[System Application / System Application]
  <C:\WINDOWS\Hacker.com.cn.exe><N/A>
==================================
浏览器加载项
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>

欢迎来到(www.dngz.net)


[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\QQ2005\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Yahoo Toolbar]
  {4FF076DA-65DB-4F71-A5D0-D022E2F64E97} <C:\WINDOWS\system32\ibrowser.dll, N/A>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation> dngz.net您的电脑医生
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>


[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\QQ2005\AddToNetDisk.htm, N/A>

dngz.net版权所有


[添加到QQ自定义面板]
  <C:\Program Files\QQ2005\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\QQ2005\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\QQ2005\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 424][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 480][\?\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 504][\?\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 548][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 560][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 712][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 756][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)> 本文来自 www.dngz.net
[PID: 864][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 944][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1012][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1248][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1372][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1744][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1024][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1732][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 208][C:\Documents and Settings\new\桌面\17aqkkan\空空的按钮突破专家\空空的按钮突破专家.exe]  <N/A><N/A>
[PID: 6996][F:\HLSW中文版\HLSW中文版\HLSW1.0.0.15.exe]  <><1, 0, 0, 1>

(www.dngz.net)版权所有


[PID: 6980][D:\Octopus\Server.exe]  <吉胜科技><15.4.11.896>
    [D:\Octopus\printcard.dll]  <N/A><N/A>
    [D:\Octopus\icdevice.dll]  <N/A><N/A>
    [D:\Octopus\remoteclientdll.dll]  <N/A><N/A>
    [D:\Octopus\regcode.dll]  <N/A><N/A>
    [D:\Octopus\rzx.dll]  <成都吉胜科技><1.1.0.622>
    [D:\Octopus\Iplist.dll]  <N/A><N/A>
    [D:\Octopus\wxhelper.dll]  <成都吉胜科技有限公司><1.1.0.6536>
    [D:\Octopus\idlogupload.dll]  <深圳任子行网络技术公司><2.0>
    [D:\Octopus\NBConfig.dll]  <><1, 0, 0, 1>
    [D:\Octopus\LanSet.dll]  <N/A><N/A>
    [D:\Octopus\DynaSet.dll]  <><1, 0, 0, 1>
[PID: 7052][D:\Octopus\rzxsurename.exe]  <深圳任子行网络技术公司><2.0>
    [D:\Octopus\NetManageIDCard.dll]  <N/A><N/A>
    [D:\Octopus\GCardID_RZX.dll]  <N/A><N/A>
    [D:\Octopus\idcardupdown.dll]  <深圳任子行网络技术公司><2.0>
    [D:\Octopus\NBConfig.dll]  <><1, 0, 0, 1>
    [D:\Octopus\LanSet.dll]  <N/A><N/A> (www.dngz.net)版权所有
    [D:\Octopus\DynaSet.dll]  <><1, 0, 0, 1>
    [D:\Octopus\idlogupload.dll]  <深圳任子行网络技术公司><2.0>
    [D:\Octopus\IPList.dll]  <N/A><N/A>
    [D:\Octopus\IDApi.dll]  <深圳任子行网络技术公司><2.0>
[PID: 956][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 5200][C:\Program Files\木马杀客\mmsk.exe]  <木马杀客><2,0,0,6>
    [C:\Program Files\木马杀客\krnln.fnr]  <><1, 0, 0, 1>
    [C:\Program Files\木马杀客\iext2.fne]  <><1, 0, 0, 1>
    [C:\Program Files\木马杀客\iext.fne]  <><1, 0, 0, 1>
    [C:\Program Files\木马杀客\HYExtLib.fne]  <N/A><N/A>
    [C:\Program Files\木马杀客\HtmlView.fne]  <><1, 0, 0, 1>
    [C:\Program Files\木马杀客\TrayIcon.fne]  <><1, 0, 0, 1>
    [C:\Program Files\木马杀客\iext3.fne]  <><1, 0, 0, 1>
    [C:\Program Files\木马杀客\xplib.fne]  <N/A><N/A>
    [C:\Program Files\木马杀客\mmskskin.dll]  <><2, 0, 0, 6>
    [C:\Program Files\木马杀客\SkinPPWTL.dll]  <http://www.skinplusplus.com><2, 1, 0, 0> .
    [C:\Program Files\木马杀客\shell.fne]  <N/A><N/A>
    [C:\Program Files\木马杀客\EThread.fne]  <N/A><N/A>
    [C:\Program Files\木马杀客\dp1.fne]  <N/A><N/A>
    [C:\Program Files\木马杀客\eAPI.fne]  <><1, 0, 0, 1>
[PID: 768][F:\ha_hijackthis_1991\HijackThis.exe]  <Soeperman Enterprises Ltd.><1.99.0001>
[PID: 896][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\QQ2005\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[PID: 3944][F:\sreng\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]

dngz.net您的电脑医生


.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
标签: