EXEÎļþÈ«±»³ÔÁË£¬ÕâÊÇʲô²¡¶¾£¿
2007-12-19 23:53:24.0
EXEÎļþÈ«±»³ÔÁË£¬ÕâÊÇʲô²¡¶¾£¿

[ ±¾Ìû×îºóÓÉ ·çԴʹÕß ÓÚ 2007-6-6 00:19 ±à¼­ ]



ʲôÒâ˼£¿EXEÎļþÈ«±»É¾³ýÁË£¿

ÏÂÔØÖ´ÐÐSystem Repair Engineer (SREng)

°´¡¸ÖÇÄÜɨÃ衹£¬ÔÙ°´¡¸É¨Ã衹
×îºó£¬°´¡¸±£´æ±¨¸æ¡¹£¬±£´æµ½×ÀÃæ
½« SREngLOG.log ÖÐÄÚÈÝÍêÕûµÄ¸´ÖÆÕ³ÌùÉÏÀ´£¬²»Òª×öÈκÎÐ޸ġ£
Èç³öÏÖÎÞ·¨ÔËÐУ¬ÇëÖØÃüÃû»òÐÞ¸ÄÀ©Õ¹Ãû£¬Èçxic.exe/xic.com/xic.bat/xic.scrµÈ



ºÃÁË£¬Âé·³Äã¿´¿´
¸´ÖÆÄÚÈݵ½¼ôÌù°å
´úÂë:
2007-06-06,00:26:10

System Repair Engineer 2.4.12.806
Smallfrogs ([url]http://www.KZTechs.com[/url])

Windows XP Professional Service Pack 2 (Build 2600) - ¹ÜÀíȨÏÞÓû§ - ÍêÕû¹¦ÄÜ

ÒÔÏÂÄÚÈݱ»Ñ¡ÖУº
    ËùÓÐµÄÆô¶¯ÏîÄ¿£¨°üÀ¨×¢²á±í¡¢Æô¶¯Îļþ¼Ð¡¢·þÎñµÈ£©
    ä¯ÀÀÆ÷¼ÓÔØÏî
    ÕýÔÚÔËÐеĽø³Ì£¨°üÀ¨½ø³ÌÄ£¿éÐÅÏ¢£©
    Îļþ¹ØÁª
    Winsock ÌṩÕß
    Autorun.inf
    HOSTS Îļþ


Æô¶¯ÏîÄ¿
×¢²á±í
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <Super Rabbit IEPro><C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <load><C:\WINDOWS\uninstall\rundl132.exe>  []
    <MsIMMs32><C:\WINDOWS\MsIMMs32.exe>  []
    <dasa><C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso.exe>  []
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <MSDEG32><LYLoader.exe>  []
    <MSDWG32><LYLoadbr.exe>  [N/A]
    <MSDCG32    ><LYLeador.exe>  [N/A]
    <MSDOG32><LYLoador.exe>  [N/A]
    <MSDSG32><LYLoadar.exe>  [N/A]
    <MSDMG32><LYLoadmr.exe>  []
    <MSDHG32><LYLoadhr.exe>  [N/A]
    <MSDQG32><LYLoadqr.exe>  [N/A]
    <twin><C:\WINDOWS\system32\ctfnom.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{1496D5ED-7A09-46D0-8C92-B8E71A4304DF}><C:\WINDOWS\system32\msacn.dll>  []

==================================
Æô¶¯Îļþ¼Ð
N/A

==================================
·þÎñ
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Win32 Debug Service / MSDebugsvc][Stopped/Auto Start]
  <C:\WINDOWS\system32\rundll32.exe msdebug.dll,input><Microsoft Corporation>
[Remote Help Session Manager / Rasautol][Stopped/Auto Start]
  <C:\WINDOWS\system32\ntsokele.exe><N/A>
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
  <C:\WINDOWS\system32\rundll32.exe windds32.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
  <C:\WINDOWS\system32\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[WinZXServiceNow / WinZXServiceNow][Stopped/Auto Start]
  <C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\RAVZX.EXE><N/A>
[WMI Performance API / WMIApiSrv][Stopped/Auto Start]
  <C:\WINDOWS\system32\rundll32.exe WMIApiSrv.dll,input><Microsoft Corporation>

==================================
Çý¶¯³ÌÐò
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\F:\Tencent\qq\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>

==================================
ä¯ÀÀÆ÷¼ÓÔØÏî
[³¬¼¶ÍÃ×ÓÉÏÍø¾«Áé]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[³¬¼¶ÍÃ×ÓÉÏÍø¾«Áé]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[³¬¼¶ÍÃ×ÓÉÏÍø¾«Áé]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[³¬¼¶ÍÃ×ÓÉÏÍø¾«Áé]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Microsoft Web ä¯ÀÀÆ÷]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>

==================================
ÕýÔÚÔËÐеĽø³Ì
[PID: 420][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 548][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\LYMANGR.DLL]  [N/A, ]
[PID: 560][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RAVZX531.dll]  [N/A, ]
[PID: 724][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
[PID: 772][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 836][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 1356][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\wscsv.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\SHQMANGR.DLL]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Real\RealPlayer\rpshell.dll]  [RealNetworks, Inc., 1.0.1.1946]
    [C:\WINDOWS\system32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
    [C:\Program Files\Real\RealPlayer\lang\rpext_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
[PID: 1672][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3208]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
[PID: 1680][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
[PID: 1688][C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE]  [Super Rabbit Soft, 7.98]
    [C:\WINDOWS\system32\msvbvm60.dll]  [Microsoft Corporation, 6.00.9690]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\PROGRA~1\SUPERR~1\MagicSet\shlobj71.ocx]  [Sky Software ([url]http://www.ssware.com[/url]), 7, 1, 0, 0]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
[PID: 1744][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
[PID: 1232][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
[PID: 2016][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
[PID: 1432][C:\WINDOWS\system32\cmd.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
[PID: 404][F:\Tencent\qq\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [F:\Tencent\qq\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\BasicCtrlDll.dll]  [Tencent, 7, 0, 101, 80]
    [F:\Tencent\qq\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [F:\Tencent\qq\QQ\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [F:\Tencent\qq\QQ\PYKer.dll]  [Æ®ÔÆ [url]http://www.pyqq.cn[/url], Æ®ÔÆ]
    [F:\Tencent\qq\QQ\ipsearcher.dll]  [, 1.0.0.3]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [F:\Tencent\qq\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [F:\Tencent\qq\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\LoginCtrl.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [F:\Tencent\qq\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [F:\Tencent\qq\QQ\LoginCtrlRes.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQMainFrame.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\CQQApplication.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQKnowledgeSearch.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQAllInOne.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\GroupLive.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [F:\Tencent\qq\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\Tencent\qq\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [F:\Tencent\qq\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\Tencent\qq\QQ\QQAvatar.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQPlugin.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [F:\Tencent\qq\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQCustomFace.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\QRingMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [F:\Tencent\qq\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQSysMsgMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\BQQApplication.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\PersonalDesktop.dll]  [ÉîÛÚÊÐÌÚѶ¼ÆËã»úϵͳ¹«Ë¾QQ¹¤×÷С×é, 1, 0, 0, 2]
    [F:\Tencent\qq\QQ\QQAddr.dll]  [ÉîÛÚÊÐÌÚѶ¼ÆËã»úϵͳÓÐÏÞ¹«Ë¾, 5, 0, 101, 280]
    [F:\Tencent\qq\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [F:\Tencent\qq\QQ\QQSceneMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [F:\Tencent\qq\QQ\QQPhoneHelper.dll]  [ÌÚѶ¿Æ¼¼£¨ÉîÛÚ£©ÓÐÏÞ¹«Ë¾, 2, 1, 9, 92]
    [F:\Tencent\qq\QQ\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [F:\Tencent\qq\QQ\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 1108][F:\Tencent\qq\QQ\TIMPlatfrom.exe]  [tencent, 0, 3, 1, 8]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1764][C:\Program Files\PPStream\PPStream.exe]  [PPStream.com, 1, 0, 4, 701]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\PROGRA~1\PPStream\POWERP~1.DLL]  [PPStream Inc., 1,0,0,3000]
    [C:\PROGRA~1\PPStream\PSNetwork.dll]  [PPStream, inc., 1, 0, 0, 2442]
    [C:\PROGRA~1\PPStream\POWERL~1.OCX]  [PPStream.com, 1, 0, 0, 1982]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx]  [Macromedia, Inc., 6,0,88,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
[PID: 228][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll]  [Xiang Feng Technology, 2, 2, 0, 1612]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 1196][C:\Documents and Settings\richweiwei\×ÀÃæ\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]

==================================
Îļþ¹ØÁª
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock ÌṩÕß
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS Îļþ
127.0.0.1       localhost

==================================
API HOOK
N/A

==================================
Òþ²Ø½ø³Ì
N/A

==================================




ÔÚ¡¸ÎҵĵçÄÔ¡¹Éϰ´ÓÒ¼ü£¬Ñ¡Ôñ¡¸ÊôÐÔ¡¹
½øÈ롸ϵͳ»¹Ô­¡¹£¬¹´Ñ¡¡¸ÔÚËùÓÐÇý¶¯Æ÷ÉϹرÕϵͳ»¹Ô­¡¹£¬°´Ï¡¸Ó¦Óá¹£¬³öÏÖÌáʾ¶Ô»°¿òʱ°´¡¸ÊÇ¡¹£¨²¡¶¾ÇåÀíºóÇë×Ô¼º¾ö¶¨ÊÇ·ñ´ò¿ªÏµÍ³»¹Ô­£©

µã´ËÏÂÔØATF Cleaner
Ö´Ðк󣬹´Ñ¡¡¸È«Ñ¡¡¹£¬°´Ï¡¸Á¢¿ÌÇåÀí¡¹

¸ù¾ÝSREngɨÃèÈÕÖ¾Çë°´ÕÕÈçϲ½Ö裬³¢ÊÔɾ³ýºÍÐÞ¸´

1.½¨ÒéʹÓÃXDelBoxɾ³ýÒÔÏÂÎļþ£º(XDelBoxÏÂÔØ)
ʹÓÃ˵Ã÷£ºÉ¾³ýʱ¸´ÖÆËùÓÐҪɾ³ýÎļþµÄ·¾¶£¬ÔÚ´ýɾ³ýÎļþÁбíÀïµã»÷ÓÒ¼üÑ¡Ôñ´Ó¼ôÌù°åµ¼È룬µ¼ÈëºóÔÚҪɾ³ýÎļþÉϵã»÷ÓÒ¼ü£¬Ñ¡ÔñÁ¢¿ÌÖØÆôɾ³ý£¬µçÄÔ»áÖØÆô½øÈëDOS½çÃæ½øÐÐɾ³ý²Ù×÷¡£ÔËÐÐxdelboxǰ×îºÃÐ¶ÔØËùÓпÉÒÆ¶¯´æ´¢½éÖÊ£¨°üÀ¨UÅÌ£¬MP3£¬ÊÖ»ú´æ´¢¿¨µÈ£©¡£
(ÈçXDelBoxÌáʾÎļþ²»´æÔڵģ¬ºöÂÔ¼´¿É)

c:\windows\system32\lymangr.dll
c:\windows\system32\ravzx531.dll
c:\windows\system32\fksdy.dll
c:\windows\system32\hreax.dll
c:\windows\system32\wfdrd.dll
c:\windows\system32\wgptl.dll
c:\windows\system32\wtrmm.dll
c:\windows\system32\zkjjx.dll
c:\docume~1\richwe~1\locals~1\temp\daso0.dll
c:\windows\system32\msimms32.dll
c:\windows\system32\shqmangr.dll
c:\windows\system32\wscsv.dll
c:\windows\system32\msdebug.dll
c:\windows\system32\windds32.dll
c:\windows\system32\windhcp.ocx
c:\windows\system32\wmiapisrv.dll
c:\windows\system32\msacn.dll
c:\windows\system32\lyloadqr.exe
c:\docume~1\richwe~1\locals~1\temp\daso.exe
c:\windows\msimms32.exe
c:\windows\uninstall\rundl132.exe
c:\windows\system32\ctfnom.exe
c:\windows\system32\ntsokele.exe
c:\docume~1\richwe~1\locals~1\temp\ravzx.exe
c:\windows\system32\drivers\npf.sys

2.ɾ³ýÖØÆôºóʹÓÃSREngÐÞ¸´ÏÂÃæ¸÷Ï

    Æô¶¯ÏîÄ¿ £­£­ ×¢²á±íÖ®ÈçÏÂÏîɾ³ý£º
[{1496D5ED-7A09-46D0-8C92-B8E71A4304DF}]    <C:\WINDOWS\system32\msacn.dll>
[MSDQG32]    <LYLoadqr.exe>
[MSDHG32]    <LYLoadhr.exe>
[MSDMG32]    <LYLoadmr.exe>
[MSDSG32]    <LYLoadar.exe>
[MSDOG32]    <LYLoador.exe>
[MSDCG32    ]    <LYLeador.exe>
[MSDWG32]    <LYLoadbr.exe>
[MSDEG32]    <LYLoader.exe>
[dasa]    <C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso.exe>
[MsIMMs32]    <C:\WINDOWS\MsIMMs32.exe>
[load]    <C:\WINDOWS\uninstall\rundl132.exe>
[twin]    <C:\WINDOWS\system32\ctfnom.exe>

    Æô¶¯ÏîÄ¿ £­£­ ·þÎñ £­£­ Win32·þÎñÓ¦ÓóÌÐòÖ®ÈçÏÂÏîɾ³ý£º
[Win32 Debug Service / MSDebugsvc]    <C:\WINDOWS\system32\rundll32.exe msdebug.dll,input>
[Remote Help Session Manager / Rasautol]    <C:\WINDOWS\system32\ntsokele.exe>
[Win32 Display Driver / Win32DDS]    <C:\WINDOWS\system32\rundll32.exe windds32.dll,input>
[Windows DHCP Service / WinDHCPsvc]    <C:\WINDOWS\system32\rundll32.exe windhcp.ocx,input>
[WinZXServiceNow / WinZXServiceNow]    <C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\RAVZX.EXE>
[WMI Performance API / WMIApiSrv]    <C:\WINDOWS\system32\rundll32.exe WMIApiSrv.dll,input>

    Æô¶¯ÏîÄ¿ £­£­ ·þÎñ£­£­ Çý¶¯³ÌÐòÖ®ÈçÏÂÏîɾ³ý£º
[Netgroup Packet Filter / NPF]    <system32\drivers\npf.sys>

×îºóÏÂÔØwindowsÇåÀíÖúÊÖÇåÀí¶ñÒâÈí¼þÒÔ¼°×ÔÉíɱÈíÉý¼¶ÖÁ×îУ¬½øÐÐÈ«ÅÌɱ¶¾
http://www.arswp.com/download/arswp/arswp.rar



лл·çÔ´¡¡¡¡¡¡¡¡



ÎÊÌâ½â¾öÇëÐ޸ıêÌâÒѽâ¾ö¡£




±êÇ©£º
֤ȯ/Àí²Æ ¹ÉƱ ÊÕÅÌ µãÆÀ ¿Õ·½ ¶à·½ ϵø 11111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111
Ïà¹ØÎÄÕÂ:
ÎÄÕÂÆÀÂÛ
[ÒÔÏÂÍøÓÑÁôÑÔÖ»´ú±íÆä¸öÈ˹۵㣬²»´ú±íÖлªÍøµÄ¹Ûµã»òÁ¢³¡]
·¢±íÆÀÂÛ
êÇ ³Æ£º
Ö÷ Ò³£º
ÄÚ ÈÝ£º
±í Ç飺

 
 
>     [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
[PID: 404][F:\Tencent\qq\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [F:\Tencent\qq\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\BasicCtrlDll.dll]  [Tencent, 7, 0, 101, 80]
    [F:\Tencent\qq\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [F:\Tencent\qq\QQ\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [F:\Tencent\qq\QQ\PYKer.dll]  [Æ®ÔÆ [url]http://www.pyqq.cn[/url], Æ®ÔÆ]
    [F:\Tencent\qq\QQ\ipsearcher.dll]  [, 1.0.0.3]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [F:\Tencent\qq\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [F:\Tencent\qq\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\LoginCtrl.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [F:\Tencent\qq\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [F:\Tencent\qq\QQ\LoginCtrlRes.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQMainFrame.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\CQQApplication.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQKnowledgeSearch.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQAllInOne.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\GroupLive.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [F:\Tencent\qq\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\Tencent\qq\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [F:\Tencent\qq\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\Tencent\qq\QQ\QQAvatar.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQPlugin.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [F:\Tencent\qq\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQCustomFace.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\QRingMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [F:\Tencent\qq\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQSysMsgMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\BQQApplication.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\PersonalDesktop.dll]  [ÉîÛÚÊÐÌÚѶ¼ÆËã»úϵͳ¹«Ë¾QQ¹¤×÷С×é, 1, 0, 0, 2]
    [F:\Tencent\qq\QQ\QQAddr.dll]  [ÉîÛÚÊÐÌÚѶ¼ÆËã»úϵͳÓÐÏÞ¹«Ë¾, 5, 0, 101, 280]
    [F:\Tencent\qq\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [F:\Tencent\qq\QQ\QQSceneMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [F:\Tencent\qq\QQ\QQPhoneHelper.dll]  [ÌÚѶ¿Æ¼¼£¨ÉîÛÚ£©ÓÐÏÞ¹«Ë¾, 2, 1, 9, 92]
    [F:\Tencent\qq\QQ\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [F:\Tencent\qq\QQ\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 1108][F:\Tencent\qq\QQ\TIMPlatfrom.exe]  [tencent, 0, 3, 1, 8]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1764][C:\Program Files\PPStream\PPStream.exe]  [PPStream.com, 1, 0, 4, 701]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\PROGRA~1\PPStream\POWERP~1.DLL]  [PPStream Inc., 1,0,0,3000]
    [C:\PROGRA~1\PPStream\PSNetwork.dll]  [PPStream, inc., 1, 0, 0, 2442]
    [C:\PROGRA~1\PPStream\POWERL~1.OCX]  [PPStream.com, 1, 0, 0, 1982]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx]  [Macromedia, Inc., 6,0,88,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
[PID: 228][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll]  [Xiang Feng Technology, 2, 2, 0, 1612]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 1196][C:\Documents and Settings\richweiwei\×ÀÃæ\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]

==================================
Îļþ¹ØÁª
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock ÌṩÕß
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS Îļþ
127.0.0.1       localhost

==================================
API HOOK
N/A

==================================
Òþ²Ø½ø³Ì
N/A

==================================



ÔÚ¡¸ÎҵĵçÄÔ¡¹Éϰ´ÓÒ¼ü£¬Ñ¡Ôñ¡¸ÊôÐÔ¡¹
½øÈ롸ϵͳ»¹Ô­¡¹£¬¹´Ñ¡¡¸ÔÚËùÓÐÇý¶¯Æ÷ÉϹرÕϵͳ»¹Ô\lymangr.dll
c:\windows\system32\ravzx531.dll
c:\windows\syste­
¡¹£¬°´Ï¡¸Ó¦Óá¹£¬³öÏÖÌáʾ¶Ô»°¿òʱ°´¡¸ÊÇ¡¹£¨²¡¶¾ÇåÀíºóÇë×Ô¼º¾ö¶¨ÊÇ·ñ´ò¿ªÏµÍ³»¹Ô­£©

µã´ËÏÂÔØATF Cleaner
Ö´Ðк󣬹´Ñ¡¡¸È«Ñ¡¡¹£¬°´Ï¡¸Á¢¿ÌÇåÀí¡¹

¸ù¾ÝSREngɨÃèÈÕÖ¾Çë°´ÕÕÈçϲ½Ö裬³¢ÊÔɾ³ýºÍÐÞ¸´

1.½¨ÒéʹÓÃXDelBoxɾ³ýÒÔÏÂÎļþ£º(XDelBoxÏÂÔØ)
ʹÓÃ˵Ã÷£ºÉ¾³ýʱ¸´ÖÆËùÓÐҪɾ³ýÎļþµÄ·¾¶£¬ÔÚ´ýɾ³ýÎļþÁбíÀïµã»÷ÓÒ¼üÑ¡Ôñ´Ó¼ôÌù°åµ¼È룬µ¼ÈëºóÔÚҪɾ³ýÎļþÉϵã»÷ÓÒ¼ü£¬Ñ¡ÔñÁ¢¿ÌÖØÆôɾ³ý£¬µçÄÔ»áÖØÆô½øÈëDOS½çÃæ½øÐÐɾ³ý²Ù×÷¡£ÔËÐÐxdelboxǰ×îºÃÐ¶ÔØËùÓпÉÒÆ¶¯´æ´¢½éÖÊ£¨°üÀ¨UÅÌ£¬MP3£¬ÊÖ»ú´æ´¢¿¨µÈ£©¡£
(ÈçXDelBoxÌáʾÎļþ²»´æÔڵģ¬ºöÂÔ¼´¿É)

c:\windows\system32\lymangr.dll
c:\windows\system32\ravzx531.dll
c:\windows\system32\fksdy.dll
c:\windows\system32\hreax.dll
c:\windows\system32\wfdrd.dll
c:\windows\system32\wgptl.dll
c:\windows\system32\wtrmm.dll
c:\windows\system32\zkjjx.dll
c:\docume~1\richwe~1\locals~1\temp\daso0.dll
c:\windows\system32\msimms32.dll
c:\windows\system32\shqmangr.dll
c:\windows\system32\wscsv.dll
c:\windows\system32\msdebug.dll
c:\windows\system32\windds32.dll
c:\windows\system32\windhcp.ocx
c:\windows\system32\wmiapisrv.dll
c:\windows\system32\msacn.dll
c:\windows\system32\lyloadqr.exe
c:\docume~1\richwe~1\locals~1\temp\daso.exe
c:\windows\msimms32.exe
c:\windows\uninstall\rundl132.exe
c:\windows\system32\ctfnom.exe
c:\windows\system32\ntsokele.exe
c:\docume~1\richwe~1\locals~1\temp\ravzx.exe
c:\windows\system32\drivers\npf.sys

2.ɾ³ýÖØÆôºóʹÓÃSREngÐÞ¸´ÏÂÃæ¸÷Ï

    Æô¶¯ÏîÄ¿ £­£­ ×¢²á±íÖ®ÈçÏÂÏîɾ³ý£º
[{1496D5ED; <C:\WINDOWS\system32\ntsokele.exe>
[Win32 Display Driver / Win32DDS]    <C:\WINDOWS\system32\rundll32.exe windds32.dll,input>
[Windows DHCP Service / WinDHCPsvc]    <C:\WINDOWS\system32\rundll32.exe windhcp.ocx,input>
[WinZXServiceNow / WinZXServiceNow]    <C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\RAVZX.EXE>
[WMI Performance API / WMIApiSrv]    <C:\WINDOWS\system32\rundll32.exe WMIApiSrv.dll,input>

    Æô¶¯ÏîÄ¿ £­£­ ·þÎñ£­£­ Çý¶¯³ÌÐòÖ®ÈçÏÂÏîɾ³ý£º
[Netgroup Packet Filter / NPF]    <system32\drivers\npf.sys>

×îºóÏÂÔØwindowsÇåÀíÖúÊÖÇåÀí¶ñÒâÈí¼þÒÔ¼°×ÔÉíɱÈíÉý¼¶ÖÁ×îУ¬½øÐÐÈ«ÅÌɱ¶¾
http://www.arswp.com/download/arswp/arswp.rar



лл·çÔ´¡¡¡¡¡¡¡¡



ÎÊÌâ½â¾öÇëÐ޸ıêÌâÒѽâ¾ö¡£




±êÇ©£º
֤ȯ/Àí²Æ ¹ÉƱ ÊÕÅÌ µãÆÀ ¿Õ·½ ¶à·½ ϵø 11111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111
Ïà¹ØÎÄÕÂ:
ÎÄÕÂÆÀÂÛ
[ÒÔÏÂÍøÓÑÁôÑÔÖ»´ú±íÆä¸öÈ˹۵㣬²»´ú±íÖлªÍøµÄ¹Ûµã»òÁ¢³¡]
·¢±íÆÀÂÛ
êÇ ³Æ£º
Ö÷ Ò³£º
ÄÚ ÈÝ£º
±í Ç飺

 
 
>     [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
[PID: 404][F:\Tencent\qq\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [F:\Tencent\qq\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\BasicCtrlDll.dll]  [Tencent, 7, 0, 101, 80]
    [F:\Tencent\qq\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [F:\Tencent\qq\QQ\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [F:\Tencent\qq\QQ\PYKer.dll]  [Æ®ÔÆ [url]http://www.pyqq.cn[/url], Æ®ÔÆ]
    [F:\Tencent\qq\QQ\ipsearcher.dll]  [, 1.0.0.3]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [F:\Tencent\qq\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [F:\Tencent\qq\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\LoginCtrl.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [F:\Tencent\qq\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [F:\Tencent\qq\QQ\LoginCtrlRes.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQMainFrame.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\CQQApplication.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQKnowledgeSearch.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQAllInOne.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\GroupLive.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [F:\Tencent\qq\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\Tencent\qq\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [F:\Tencent\qq\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\Tencent\qq\QQ\QQAvatar.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQPlugin.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [F:\Tencent\qq\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQCustomFace.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\QRingMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [F:\Tencent\qq\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\QQSysMsgMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\BQQApplication.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [F:\Tencent\qq\QQ\PersonalDesktop.dll]  [ÉîÛÚÊÐÌÚѶ¼ÆËã»úϵͳ¹«Ë¾QQ¹¤×÷С×é, 1, 0, 0, 2]
    [F:\Tencent\qq\QQ\QQAddr.dll]  [ÉîÛÚÊÐÌÚѶ¼ÆËã»úϵͳÓÐÏÞ¹«Ë¾, 5, 0, 101, 280]
    [F:\Tencent\qq\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [F:\Tencent\qq\QQ\QQSceneMng.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [F:\Tencent\qq\QQ\QQPhoneHelper.dll]  [ÌÚѶ¿Æ¼¼£¨ÉîÛÚ£©ÓÐÏÞ¹«Ë¾, 2, 1, 9, 92]
    [F:\Tencent\qq\QQ\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [F:\Tencent\qq\QQ\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 1108][F:\Tencent\qq\QQ\TIMPlatfrom.exe]  [tencent, 0, 3, 1, 8]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [F:\Tencent\qq\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1764][C:\Program Files\PPStream\PPStream.exe]  [PPStream.com, 1, 0, 4, 701]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\PROGRA~1\PPStream\POWERP~1.DLL]  [PPStream Inc., 1,0,0,3000]
    [C:\PROGRA~1\PPStream\PSNetwork.dll]  [PPStream, inc., 1, 0, 0, 2442]
    [C:\PROGRA~1\PPStream\POWERL~1.OCX]  [PPStream.com, 1, 0, 0, 1982]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx]  [Macromedia, Inc., 6,0,88,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
[PID: 228][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll]  [Xiang Feng Technology, 2, 2, 0, 1612]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 1196][C:\Documents and Settings\richweiwei\×ÀÃæ\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\system32\msdebug.dll]  [N/A, ]
    [C:\WINDOWS\system32\windds32.dll]  [N/A, ]
    [C:\WINDOWS\system32\windhcp.ocx]  [N/A, ]
    [C:\WINDOWS\system32\WMIApiSrv.dll]  [N/A, ]
    [C:\WINDOWS\system32\zkjjx.dll]  [N/A, ]
    [C:\WINDOWS\system32\wfdrd.dll]  [N/A, ]
    [C:\WINDOWS\system32\hreax.dll]  [N/A, ]
    [C:\WINDOWS\system32\wtrmm.dll]  [N/A, ]
    [C:\WINDOWS\system32\wgptl.dll]  [N/A, ]
    [C:\WINDOWS\system32\fksdy.dll]  [N/A, ]
    [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
    [C:\DOCUME~1\RICHWE~1\LOCALS~1\Temp\daso0.dll]  [N/A, ]

==================================
Îļþ¹ØÁª
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock ÌṩÕß
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS Îļþ
127.0.0.1       localhost

==================================
API HOOK
N/A

==================================
Òþ²Ø½ø³Ì
N/A

==================================



ÔÚ¡¸ÎҵĵçÄÔ¡¹Éϰ´ÓÒ¼ü£¬Ñ¡Ôñ¡¸ÊôÐÔ¡¹
½øÈ롸ϵͳ»¹Ô­¡¹£¬¹´Ñ¡¡¸ÔÚËùÓÐÇý¶¯Æ÷ÉϹرÕϵͳ»¹Ô\lymangr.dll
c:\windows\system32\ravzx531.dll
c:\windows\syste