热门标签 | HotTags
当前位置:  开发笔记 > 编程语言 > 正文

中毒了,求助!!

我用的是金山的alcmtr,中毒了,病毒是Win32.Adware.WSearch.o.98304帮忙看一下alcmtr

我用的是金山的alcmtr,中毒了,病毒是Win32.Adware.WSearch.o.98304

  帮忙看一下alcmtr,注册表的情况如下:

  [CODE]

  2007-05-10,08:53:37

  System Repair Engineer 2.3.13.690

  Smallfrogs ()

  Windows XP Professional Service Pack 2 (Build 2600)

   - 管理权限用户 - 完整功能

  以下内容被选中:

   所有的启动项目(包括注册表、启动文件夹、服务等)

   浏览器加载项

   正在运行的进程(包括进程模块信息)

   文件关联

   Winsock 提供者

   Autorun.inf

   HOSTS 文件

  启动项目

  注册表

  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

   <"C:\kav2005\KPFW32.EXE"> [Kingsoft Corporation]

   <; C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]

   <; "C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Corporation]

   <; "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup> [Cyberlink]

   <; C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe> [N/A]

  [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]

   <> [N/A]

  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

   <"C:\kav2005\KAVStart.exe" -startup> [Kingsoft Corporation]

   [(Verified)Microsoft Corporation]

   [SnowFox Studio.]

   <; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]

   <; ALCMTR.EXE> [(Verified)Realtek Semiconductor Corp.]

   <; C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe> [N/A]

   <; C:\Program Files\Lenovo\EnergyCut\utilty.exe> [TODO: ]

   <; "C:\Program Files\Launch Manager\HotkeyApp.exe"> [Wistron]

   <; > [N/A]

   <; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation]

   <; C:\WINDOWS\system32\igfxpers.exe> [(Verified)Intel Corporation]

   <; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation]

   <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]

   <; > [N/A]

   <; "C:\Program Files\Launch Manager\LaunchAp.exe"> [N/A]

   <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]

   <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]

中毒了,求助!!

   <; RTHDCPL.EXE> [(Verified)Realtek Semiconductor Corp.]

   <; SkyTel.EXE> [(Verified)Realtek Semiconductor Corp.]

   <; C:\WINDOWS\sm56hlpr.exe> [(Verified)Motorola Inc.]

   <; C:\PROGRA~1\TENCENT\Adplus\stup.exe> [N/A]

   <; C:\Program Files\Uninstall Information\tddhcig.exe> [N/A]

   <; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]

   <; C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [(Verified)深圳市迅雷网络技术有限公司]

  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

   [(Verified)Microsoft Corporation]

   [(Verified)Microsoft Corporation]

  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]

   <> [N/A]

  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

   [(Verified)Microsoft Corporation]

  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]

   [(Verified)Intel Corporation]

  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

   [(Verified)Microsoft Corporation]

  启动文件夹

  N/A

中毒了,求助!!

  服务

  [ASP.NET State Service / aspnet_state][Stopped/Manual Start]

  

  [Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]

   <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe">

  [Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]

   <"C:\kav2005\KPfwSvc.EXE">

  [Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]

  

  [Windows pkeb RunThem / pkeb][Stopped/Auto Start]

   C:\PROGRA~1\kfzw\upjg.dll>

  驱动程序

  [Lenovo Virtual Power Controller Driver / ACPIVPC][Running/Manual Start]

  

  [ADProt / ADProt][Stopped/System Start]

   <\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>

  [Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]

  

  [epqbcam / epqbcam][Running/Boot Start]

   <\SystemRoot\system32\drivers\epqbcam.sys><>

  [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]

  

  [ialm / ialm][Running/Manual Start]

  

  [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]

  

  [kbdru3 / kbdru3][Running/Boot Start]

   <\SystemRoot\System32\DRIVERS\kbdru3.sys>

  [KNetWch / KNetWch][Running/System Start]

   <\??\C:\kav2005\KNetWch.SYS>

  [KWatch3 / KWatch3][Running/System Start]

   <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS>

  [npkcrypt / npkcrypt][Running/Auto Start]

   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys>

  [npkcusb / npkcusb][Running/Auto Start]

   <\??\C:\Program Files\Tencent\QQ\npkcusb.sys>

  [Direct Parallel Link Driver / Ptilink][Running/Manual Start]

  

  [Secdrv / Secdrv][Stopped/Manual Start]

  

  [smserial / smserial][Running/Manual Start]

  

  [TCP/IP Protocol Driver / Tcpip][Running/System Start]

  

  [tifm21 / tifm21][Running/Manual Start]

  

  [Wbutton / Wbutton][Stopped/System Start]

   <\SystemRoot\system32\drivers\Wbutton.sys>

  [zxarmw85 / zxarmw85][Stopped/Boot Start]

   <\SystemRoot\system32\\drivers\\system32\\drivers\\%s.sys.sys>

  浏览器加载项

  [WebThunder Browser Helper]

   {00000AAA-A363-466E-BEF5-9BB68697AA7F}

  [ThunderAtOnce Class]

   {01443AEC-0FD1-40fd-9C87-E93D1494C233}

  [Adobe PDF Reader Link Helper]

   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

  [CBrowseStakeout Class]

   {55302805-482E-470E-8A57-6795A1487F90}

  [ExtentIE Class]

   {66C2C482-D4EE-42A5-AEF7-0B124F278D47}

  [Thunder Browser Helper]

   {889D2FEB-5411-4565-8998-1DD2C5261283}

  [启动迅雷5]

   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436}

  [联想]

   {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <;

  [信息检索(&R)]

   {92780B25-18CC-41C8-B9BE-3C9C571A8263}

  [启动Web迅雷]

   {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <;

  [QQ]

   {c95fe080-8f5d-11d2-a20b-00aa003c157b}

  [Messenger]

   {FB5F1910-F110-11d2-BB9E-00C04F795683}

  [Dr.eye WebPage Translation]

   {92B255FE-94E2-4BCA-958D-3926CE38913F}

  [Shockwave Flash Object]

   {D27CDB6E-AE6D-11CF-96B8-444553540000}

  [WebThunder Browser Helper]

   {00000AAA-A363-466E-BEF5-9BB68697AA7F}

  [ThunderAtOnce Class]

   {01443AEC-0FD1-40FD-9C87-E93D1494C233}

  [Adobe PDF Reader Link Helper]

   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

  [CBrowseStakeout Class]

   {55302805-482E-470E-8A57-6795A1487F90}

  [ExtentIE Class]

   {66C2C482-D4EE-42A5-AEF7-0B124F278D47}

  [Thunder Browser Helper]

   {889D2FEB-5411-4565-8998-1DD2C5261283}

  [Dr.eye WebPage Translation]

   {92B255FE-94E2-4BCA-958D-3926CE38913F}

  [Shockwave Flash Object]

   {D27CDB6E-AE6D-11CF-96B8-444553540000}

  [上传到QQ网络硬盘]

  

  [使用Web迅雷下载]

  

  [使用Web迅雷下载全部链接]

  

  [使用迅雷下载]

  

  [使用迅雷下载全部链接]

  

  [导出到 Microsoft Office Excel(&X)]

  

  [添加到QQ自定义面板]

  

  [添加到QQ表情]

  

  [用QQ彩信发送该图片]

  

  [金山毒霸反钓鱼...]

  

  正在运行的进程

  [PID: 432][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 676][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 700][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 748][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 760][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 908][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 988][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 1080][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 1132][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 1232][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 1456][C:\kav2005\KWatch.EXE] [Kingsoft Corporation, 2007, 2, 12, 84]

   [C:\kav2005\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]

   [C:\kav2005\KAEPlat.DLL] [Kingsoft Corp., 2007, 2, 4, 61]

   [C:\kav2005\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]

   [C:\kav2005\KAEUnpack.DAT] [Kingsoft Corp., 2007, 4, 12, 116]

   [C:\kav2005\KAVQuara.DLL] [Kingsoft Corporation, 2007, 1, 25, 1]

  [PID: 1520][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]

  [PID: 1716][C:\kav2005\KPfwSvc.EXE] [Kingsoft Corporation, 2007, 2, 2, 31]

  [PID: 236][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 1212][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 1660][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

  [PID: 500][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]

   [C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]

   [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.2.54.0]

   [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 8.0.0.0]

   [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 8.0.0.0]

   [C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4543]

   [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4543]

   [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4543]

   [C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4543]

   [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4543]

   [C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]

   [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 8.0.0.2006102200]

   [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]

   [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 2]

   [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 4]

   [C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]

   [C:\kav2005\KAVEXT.DLL] [Kingsoft Corporation, 2005, 8, 5, 16]

  [PID: 532][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]

  [PID: 308][D:\sreng2_PConline\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]

  文件关联

  .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]

  .EXE OK. ["%1" %*]

  .COM OK. ["%1" %*]

  .PIF OK. ["%1" %*]

  .REG OK. [regedit.exe "%1"]

  .BAT OK. ["%1" %*]

  .SCR Error. [AutoCADScriptFile]

  .CHM Error. ["hh.exe" %1]

  .HLP Error. [winhlp32.exe %1]

  .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]

  .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]

  .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]

  .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]

  .LNK OK. [{00021401-0000-0000-C000-000000000046}]

  Winsock 提供者

  N/A

  Autorun.inf

  N/A

  HOSTS 文件

  127.0.0.1 localhost

  API HOOK

  N/A

  [/CODE]


推荐阅读
author-avatar
大姑娘苍之瑜
这个家伙很懒,什么也没留下!
PHP1.CN | 中国最专业的PHP中文社区 | DevBox开发工具箱 | json解析格式化 |PHP资讯 | PHP教程 | 数据库技术 | 服务器技术 | 前端开发技术 | PHP框架 | 开发工具 | 在线工具
Copyright © 1998 - 2020 PHP1.CN. All Rights Reserved | 京公网安备 11010802041100号 | 京ICP备19059560号-4 | PHP1.CN 第一PHP社区 版权所有