瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 求救:在C盘下的Trojan.DL.Agent.cse怎么杀?附日志(4)
meteor333 - 2007-1-28 15:27:00
[PID: 384][C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe]  [Acronis, 1,0,0,227]
[PID: 412][C:\WINDOWS\system32\cisvc.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 676][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 52]
[PID: 688][C:\Program Files\Acronis\TrueImageServer\TrueImageMonitor.exe]  [Acronis, 9,1,0,3677]
    [C:\Program Files\Common Files\Acronis\Common\rpc_client.dll]  [N/A, N/A]
[PID: 696][C:\Program Files\Acronis\TrueImageServer\TimounterMonitor.exe]  [Acronis, 3.3 build 437]
[PID: 704][C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe]  [Acronis, 1,0,0,227]
[PID: 792][C:\WINDOWS\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.10.8185]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.8185]
[PID: 804][D:\新建\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [D:\新建\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\新建\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\新建\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\新建\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
[PID: 820][D:\新建\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [D:\新建\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [D:\新建\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\新建\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\新建\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\新建\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\新建\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\新建\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [D:\新建\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 836][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 984][C:\Program Files\MSN Messenger\MsnMsgr.Exe]  [Microsoft Corporation, 7.5.0324]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
[PID: 280][C:\Program Files\Messenger\Msmsgs.exe]  [Microsoft Corporation, 5.1.0639]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
[PID: 1340][D:\新建\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [D:\新建\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
[PID: 1392][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
[PID: 2136][C:\ISM\2.20\bin\nsrd.exe]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBNSR.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRAP.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\liblocal.dll]  [N/A, N/A]
[PID: 2164][C:\ISM\2.20\bin\nsrexecd.exe]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBNSR.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRAP.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\liblocal.dll]  [N/A, N/A]
[PID: 2184][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.8185]
[PID: 2200][C:\ISM\2.20\bin\portmap.exe]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\liblocal.dll]  [N/A, N/A]
[PID: 2588][C:\ISM\2.20\bin\nsrmmdbd.exe]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBNSR.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRAP.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\liblocal.dll]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBWISS.DLL]  [N/A, N/A]
[PID: 2616][C:\ISM\2.20\bin\nsrindexd.exe]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBNSR.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRAP.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\liblocal.dll]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBWISS.DLL]  [N/A, N/A]
[PID: 2632][C:\ISM\2.20\bin\nsrmmd.exe]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBNSR.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRAP.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\LIBRPC.DLL]  [N/A, N/A]
    [C:\ISM\2.20\bin\liblocal.dll]  [N/A, N/A]
[PID: 2964][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3324][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3660][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 612][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\baidu\bar\baidubar.dll]  [Baidu.com, Inc., 2, 0, 2, 124]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.5.2005092300]
    [C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll]  [金泰丰(广州)科技有限公司, 2, 3, 0, 0]
    [C:\Program Files\Tencent\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [D:\Program Files\迅雷\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll]  [Microsoft Corporation, 01.02.3000.1001]
    [C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll]  [Microsoft Corporation, 01.02.5000.1021]
    [C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-cn\mtbres.dll]  [Microsoft Corporation, 01.02.5000.1021]
    [C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll]  [深圳世强软件开发部, 2005, 8, 30, 1]
    [D:\ha\OkteSchHook\AsncnSchHook.dll]  [, 1, 0, 0, 1]
    [D:\新建\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\WNWB.IME]  [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
    [C:\WINDOWS\system32\WNWBIO.IME]  [深圳世强软件开发部 www.wnwb.com , 2005, 1, 31, 1]
    [C:\Program Files\wnwb2005\WNMKEY.DLL]  [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
[PID: 576][C:\WINDOWS\system32\cidaemon.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2424][C:\WINDOWS\system32\cidaemon.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2824][C:\Program Files\wnwb2005\wnwb.exe]  [深圳世强软件开发部 www.wnwb.com , 2005, 11, 19, 1]
    [C:\Program Files\wnwb2005\WNMKEY.DLL]  [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
[PID: 1572][D:\Rising\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  Error. ["C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1"]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================


[/CODE]
1
查看完整版本: 求救:在C盘下的Trojan.DL.Agent.cse怎么杀?附日志(4)