.Cbz664
网吧记费服务器.经常弹出网业.用木马杀客和超级兔子都查过了.什么都没有.不定时的弹出两个网页
一个是http://www.7yin.com/ 另一个是 http://www.34pp.com/ 自动保存到收藏夹每次重起都会在桌面
上生成两个快捷方式怎么删也删不掉啊
Logfile of HijackThis v1.99.1
Scan saved at 20:50:00, on 2006-9-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Octopus\Server.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\new\桌面\17aqkkan\空空的按钮突破专家\空空的按钮突破专家.exe
D:\Octopus\rzxsurename.exe
C:\Program Files\木马杀客\mmsk.exe
F:\HLSW中文版\HLSW中文版\HLSW1.0.0.15.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\alexa.exe dngz.net
F:\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\QQ2005\QQIEHelper.dll
O4 - HKLM\..\Run: [78vodreg] ; C:\WINDOWS\78vod.exe
O4 - HKLM\..\Run: [ssServ] D:\Octopus\Server.exe
O4 - HKLM\..\RunServices: [78vodreg] ; C:\WINDOWS\78vod.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe (www.dngz.net)版权所有
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) www.dngz.net
O23 - Service: RzxSevce - 深圳任子行网络技术有限公司 - d:\Program Files\rzx\Net110\RzxSevce.exe
O23 - Service: System Application - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe (file missing)
[ 本帖最后由 yaokaku 于 2006-9-15 21:05 编辑 ]
会不会和下面这个有关系
O4 - HKLM\..\Run: [78vodreg] ; C:\WINDOWS\78vod.exe
修复下面,以及后面带 file missing
O23 - Service: System Application - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe (file missing)
下面这个好象是个广告
C:\WINDOWS\system32\alexa.exe
重起后还是弹出一个网页www.78du.com 我快要疯了
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm ;
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) ;
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: RzxSevce - 深圳任子行网络技术有限公司 - d:\Program Files\rzx\Net110\RzxSevce.exe
C:\WINDOWS\78vod.exe 删除这个文件
还不行就用黄山IE 或其他上网修复软件
用System Repair Engineer 2.0.21.505 扫描个日志看看
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
这个服务不知是什么,如不熟悉,最好禁用并删除其中的rpcapd.exe和rpcapd.ini
呵呵~~~你好彩~~中了跟我一样的病毒!!下载器变种!!我花了几天才删除掉!
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
问题在这里!!参考下面地址
http://www.fcbu.com/bbs/thread-100921-1-6.html
记得删除后要重新启动电脑才行!!
我找不到Realplayer.exe 的系统进程
Logfile of HijackThis v1.99.1
Scan saved at 19:15:26, on 2006-9-16
Platform: Windows XP SP2 (WinNT 5.01.2600) dngz.net
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\new\桌面\17aqkkan\空空的按钮突破专家\空空的按钮突破专家.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\HLSW中文版\HLSW中文版\HLSW1.0.0.15.exe
D:\Octopus\Server.exe
D:\Octopus\rzxsurename.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\木马杀客\mmsk.exe
F:\ha_hijackthis_1991\HijackThis.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\QQ2005\QQIEHelper.dll
O4 - HKLM\..\Run: [ssServ] D:\Octopus\Server.exe
O4 - HKLM\..\Run: [C-Media Mixer] ; Mixer.exe /startup
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 欢迎来到(www.dngz.net)
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [91cast] ;
O4 - HKCU\..\Run: [boot-hf] ; c:\windows\BOOT-hf.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe 本文来自 www.dngz.net
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FB91923-1499-4656-9E78-532F718A6475}: NameServer = 192.168.1.95
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: RzxSevce - 深圳任子行网络技术有限公司 - d:\Program Files\rzx\Net110\RzxSevce.exe
O4 - HKCU\..\Run: [91cast] ;
就是这个了
取消启动后,搜索91cast相关并删除
用System Repair Engineer 2.0.21.505扫描结果
2006-09-16,19:35:39
System Repair Engineer 2.0.21.505 (2.0 RC 2) ,
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程?樾畔ⅲ?br>
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<91cast><; > []
<boot-hf><; c:\windows\BOOT-hf.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ssServ><D:\Octopus\Server.exe> [吉胜科技]
<C-Media Mixer><; Mixer.exe /startup> [C-Media Electronic Inc. (www.cmedia.com.tw)]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation] dngz.net
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\Windows\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
服务
[RzxSevce / RzxSevce]
<d:\Program Files\rzx\Net110\RzxSevce.exe><深圳任子行网络技术有限公司>
[System Application / System Application]
<C:\WINDOWS\Hacker.com.cn.exe><N/A>
==================================
浏览器加载项
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
欢迎来到(www.dngz.net)
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\QQ2005\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Yahoo Toolbar]
{4FF076DA-65DB-4F71-A5D0-D022E2F64E97} <C:\WINDOWS\system32\ibrowser.dll, N/A>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\QQ2005\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation> dngz.net您的电脑医生
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\QQ2005\AddToNetDisk.htm, N/A>
dngz.net版权所有
[添加到QQ自定义面板]
<C:\Program Files\QQ2005\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\QQ2005\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\QQ2005\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 424][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 480][\?\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 504][\?\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 548][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 560][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 712][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 756][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)> 本文来自 www.dngz.net
[PID: 864][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 944][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1012][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1248][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1372][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1744][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1024][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1732][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 208][C:\Documents and Settings\new\桌面\17aqkkan\空空的按钮突破专家\空空的按钮突破专家.exe] <N/A><N/A>
[PID: 6996][F:\HLSW中文版\HLSW中文版\HLSW1.0.0.15.exe] <><1, 0, 0, 1>
(www.dngz.net)版权所有
[PID: 6980][D:\Octopus\Server.exe] <吉胜科技><15.4.11.896>
[D:\Octopus\printcard.dll] <N/A><N/A>
[D:\Octopus\icdevice.dll] <N/A><N/A>
[D:\Octopus\remoteclientdll.dll] <N/A><N/A>
[D:\Octopus\regcode.dll] <N/A><N/A>
[D:\Octopus\rzx.dll] <成都吉胜科技><1.1.0.622>
[D:\Octopus\Iplist.dll] <N/A><N/A>
[D:\Octopus\wxhelper.dll] <成都吉胜科技有限公司><1.1.0.6536>
[D:\Octopus\idlogupload.dll] <深圳任子行网络技术公司><2.0>
[D:\Octopus\NBConfig.dll] <><1, 0, 0, 1>
[D:\Octopus\LanSet.dll] <N/A><N/A>
[D:\Octopus\DynaSet.dll] <><1, 0, 0, 1>
[PID: 7052][D:\Octopus\rzxsurename.exe] <深圳任子行网络技术公司><2.0>
[D:\Octopus\NetManageIDCard.dll] <N/A><N/A>
[D:\Octopus\GCardID_RZX.dll] <N/A><N/A>
[D:\Octopus\idcardupdown.dll] <深圳任子行网络技术公司><2.0>
[D:\Octopus\NBConfig.dll] <><1, 0, 0, 1>
[D:\Octopus\LanSet.dll] <N/A><N/A> (www.dngz.net)版权所有
[D:\Octopus\DynaSet.dll] <><1, 0, 0, 1>
[D:\Octopus\idlogupload.dll] <深圳任子行网络技术公司><2.0>
[D:\Octopus\IPList.dll] <N/A><N/A>
[D:\Octopus\IDApi.dll] <深圳任子行网络技术公司><2.0>
[PID: 956][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 5200][C:\Program Files\木马杀客\mmsk.exe] <木马杀客><2,0,0,6>
[C:\Program Files\木马杀客\krnln.fnr] <><1, 0, 0, 1>
[C:\Program Files\木马杀客\iext2.fne] <><1, 0, 0, 1>
[C:\Program Files\木马杀客\iext.fne] <><1, 0, 0, 1>
[C:\Program Files\木马杀客\HYExtLib.fne] <N/A><N/A>
[C:\Program Files\木马杀客\HtmlView.fne] <><1, 0, 0, 1>
[C:\Program Files\木马杀客\TrayIcon.fne] <><1, 0, 0, 1>
[C:\Program Files\木马杀客\iext3.fne] <><1, 0, 0, 1>
[C:\Program Files\木马杀客\xplib.fne] <N/A><N/A>
[C:\Program Files\木马杀客\mmskskin.dll] <><2, 0, 0, 6>
[C:\Program Files\木马杀客\SkinPPWTL.dll] <http://www.skinplusplus.com><2, 1, 0, 0> .
[C:\Program Files\木马杀客\shell.fne] <N/A><N/A>
[C:\Program Files\木马杀客\EThread.fne] <N/A><N/A>
[C:\Program Files\木马杀客\dp1.fne] <N/A><N/A>
[C:\Program Files\木马杀客\eAPI.fne] <><1, 0, 0, 1>
[PID: 768][F:\ha_hijackthis_1991\HijackThis.exe] <Soeperman Enterprises Ltd.><1.99.0001>
[PID: 896][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\QQ2005\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[PID: 3944][F:\sreng\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
dngz.net您的电脑医生
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================