瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 病毒很生气,后果很严重!!
光辉末裔 - 2007-2-15 21:25:00
能帮我看看吗,冰刃装不上,几乎每个进程中都有这2个东西加载。经常中木马,有一个rootkit.vanti.gen的病毒一直没杀掉。刚刚在线瑞星查有trojan.dl.nimaya.f 和trojan.dl.vbs.cjc而且输入法没有办法在ie里输入中文
光辉末裔 - 2007-2-15 21:30:00
[csrss.exe]
PID = 0x20c
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
csrss.exe
0x4a680000
c:\windows\system32\csrss.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Client Server Runtime Process
2002-10-07 20:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1217 (xpsp2.030429-2131)
Microsoft Corporation
NT Layer DLL
2003-05-01 16:57:50

CSRSRV.dll
0x75aa0000
C:\WINDOWS\system32\csrsrv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Client Server Runtime Process
2002-10-07 20:00:00

basesrv.dll
0x75ab0000
C:\WINDOWS\system32\basesrv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Server DLL
2002-10-07 20:00:00

winsrv.dll
0x75ac0000
C:\WINDOWS\system32\winsrv.dll
5.1.2600.1134 (xpsp2.020921-0842)
Microsoft Corporation
Windows Server DLL
2002-11-22 12:30:20

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1134 (xpsp2.020921-0842)
Microsoft Corporation
Windows XP USER API Client DLL
2002-11-22 12:30:24

KERNEL32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2002-10-07 20:00:00

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2002-10-07 20:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2002-10-07 20:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1254 (xpsp2.030801-1834)
Microsoft Corporation
Remote Procedure Call Runtime
2003-08-26 04:23:48

LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2002-10-07 20:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2002-10-07 20:00:00

sxs.dll
0x75e00000
C:\WINDOWS\system32\sxs.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Fusion 2.5
2002-10-07 20:00:00




[winlogon.exe]
PID = 0x224
CommandLine = winlogon.exe
winlogon.exe
0x1000000
c:\windows\system32\winlogon.exe
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Logon Application
2002-10-07 20:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1217 (xpsp2.030429-2131)
Microsoft Corporation
NT Layer DLL
2003-05-01 16:57:50

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2002-10-07 20:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2002-10-07 20:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2002-10-07 20:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1254 (xpsp2.030801-1834)
Microsoft Corporation
Remote Procedure Call Runtime
2003-08-26 04:23:48

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2002-10-07 20:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1134 (xpsp2.020921-0842)
Microsoft Corporation
Windows XP USER API Client DLL
2002-11-22 12:30:24

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2002-10-07 20:00:00

NDdeApi.dll
0x758a0000
C:\WINDOWS\system32\nddeapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Network DDE Share Management APIs
2002-10-07 20:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1123 (xpsp2.020921-0842)
Microsoft Corporation
Crypto API32
2002-09-23 15:10:56
UFO不幸外人 - 2007-2-15 22:02:00
先扫描SRE日志  看我的置顶帖子
光辉末裔 - 2007-2-15 22:19:00
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <runeip><D:\kaka\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><"D:\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <UnlockerAssistant><"D:\unlocker\UnlockerAssistant.exe">  [N/A]
    <Windows木马防火墙><D:\木马清道夫\Trojanwall.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><D:\kaka\RunOnce.exe>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINDOWS\System32\klogon.dll>  [Kaspersky Lab]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><; C:\WINDOWS\System32\ctfmon.exe>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [N/A]
光辉末裔 - 2007-2-15 22:20:00
==================================
启动文件夹
N/A

==================================
服务
[卡巴斯基反病毒6.0 / AVP][Stopped/Auto Start]
  <E:\avp.exe -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[PsShutdown / PsShutdownSvc][Stopped/Manual Start]
  <C:\WINDOWS\System32\PSSDNSVC.EXE><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Stopped/Auto Start]
  <d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"D:\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"D:\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Rising TDI Base Driver / BaseTDI][Stopped/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[bootdrv / bootdrv][Running/Disabled]
  <System32\Drivers\bootdrv.sys><N/A>
[ExpScaner / ExpScaner][Stopped/Auto Start]
  <\??\D:\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Stopped/Auto Start]
  <\??\D:\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Stopped/Auto Start]
  <\??\D:\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Stopped/Auto Start]
  <\??\D:\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[kl1 / kl1][Running/Boot Start]
  <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Stopped/System Start]
  <\??\C:\WINDOWS\System32\drivers\klif.sys><N/A>
[KRegEx / KRegEx][Stopped/System Start]
  <\??\D:\PROGRA~1\KV2006\KRegEx.sys><N/A>
[KvMemon / KvMemon][Stopped/Manual Start]
  <\??\D:\PROGRA~1\KV2006\KvMemon.sys><N/A>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
  <\??\D:\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Pnpnt / Pnpnt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\pnpnt.sys><N/A>
[PProtect / PProtect][Stopped/System Start]
  <\??\D:\PROGRA~1\KV2006\PProtect.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Stopped/Disabled]
  <\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Stopped/Auto Start]
  <\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
  <\??\D:\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SCatch / SCatch][Running/Auto Start]
  <System32\DRIVERS\SCatch.sys><Windows (R) 2000 DDK provider>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[TSP / TSP][Stopped/Manual Start]
  <\??\C:\WINDOWS\System32\drivers\klif.sys><N/A>

==================================
光辉末裔 - 2007-2-15 22:21:00
浏览器加载项
[FGCatchUrl]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\网际快车\jccatch.dll, www.flashget.com>
[FlashGet GetFlash Class]
  {F156768E-81EF-470C-9057-481BA8380DBA} <D:\网际快车\getflash.dll, www.flashget.com>
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <E:\scieplugin.dll, Kaspersky Lab>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[快车]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\网际快车\FlashGet.exe, FlashGet.com>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[快车(FlashGet)]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\网际士快斐车礬\fgiebar.dll, N/A>
[CKAVWebScan Object]
  {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINDOWS\System32\Kaspersky Lab\Kaspersky Online Scanner Pro\kavwebscan.dll, Kaspersky Lab>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[KvScanOnline Control]
  {EF6205C1-3F17-4829-BCB5-1336ED89E356} <C:\WINDOWS\System32\KvDown.ocx, dreamersoft>
[FGCatchUrl]
  {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <D:\网际快车\jccatch.dll, www.flashget.com>
[&使用快车(FlashGet)下载]
  <D:\网际快车\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
  <D:\网际快车\jc_all.htm, N/A>

==================================
正在运行的进程
[PID: 452][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 548][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 592][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 604][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 760][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 804][D:\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 832][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 900][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 916][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 992][D:\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
    [D:\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [D:\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [D:\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [D:\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [D:\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [D:\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 26]
[PID: 1156][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [D:\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1260][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1608][D:\kaka\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
    [D:\kaka\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1640][D:\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [D:\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1724][D:\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
    [D:\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [D:\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [D:\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2116][D:\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [D:\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 2236][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [D:\网际快车\jccatch.dll]  [www.flashget.com, 1, 8, 1, 1006]
    [D:\网际快车\getflash.dll]  [www.flashget.com, 1, 8, 1, 1002]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [E:\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [E:\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\prkernel.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [e:\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
[PID: 2372][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [D:\网际快车\jccatch.dll]  [www.flashget.com, 1, 8, 1, 1006]
    [D:\网际快车\getflash.dll]  [www.flashget.com, 1, 8, 1, 1002]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [E:\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [E:\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\prkernel.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\Downloaded Program Files\OL2005.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 2056][C:\WINDOWS\system32\NOTEPAD.EXE]  [N/A, N/A]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\System32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5076]
[PID: 2900][D:\网际快车\flashget.exe]  [FlashGet.com, 1, 8, 1, 1002]
    [D:\网际快车\FGBTCORE.dll]  [N/A, 1, 0, 0, 36]
    [D:\网际快车\fgupdate.dll]  [www.flashget.com, 1, 8, 1, 1002]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [E:\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [E:\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 4052][D:\winrar\WinRAR.exe]  [N/A, N/A]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 3252][C:\DOCUME~1\spider\LOCALS~1\Temp\Rar$EX00.791\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [D:\kaka\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
API HOOK
N/A

==================================


[/CODE]
光辉末裔 - 2007-2-15 22:32:00
WINLOGO的模块
[winlogon.exe]
PID = 0x224
CommandLine = winlogon.exe
winlogon.exe
0x1000000
c:\windows\system32\winlogon.exe
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Logon Application
2002-10-07 20:00:00

ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1217 (xpsp2.030429-2131)
Microsoft Corporation
NT Layer DLL
2003-05-01 16:57:50

kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT BASE API Client DLL
2002-10-07 20:00:00

msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2002-10-07 20:00:00

ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2002-10-07 20:00:00

RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1254 (xpsp2.030801-1834)
Microsoft Corporation
Remote Procedure Call Runtime
2003-08-26 04:23:48

GDI32.dll
0x77c40000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
GDI Client DLL
2002-10-07 20:00:00

USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1134 (xpsp2.020921-0842)
Microsoft Corporation
Windows XP USER API Client DLL
2002-11-22 12:30:24

USERENV.dll
0x759d0000
C:\WINDOWS\system32\userenv.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Userenv
2002-10-07 20:00:00
光辉末裔 - 2007-2-15 22:33:00
NDdeApi.dll
0x758a0000
C:\WINDOWS\system32\nddeapi.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Network DDE Share Management APIs
2002-10-07 20:00:00

CRYPT32.dll
0x76230000
C:\WINDOWS\system32\crypt32.dll
5.131.2600.1123 (xpsp2.020921-0842)
Microsoft Corporation
Crypto API32
2002-09-23 15:10:56

MSASN1.dll
0x76210000
C:\WINDOWS\system32\msasn1.dll
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
ASN.1 Runtime APIs
2002-10-07 20:00:00

Secur32.dll
0x76f60000
C:\WINDOWS\system32\secur32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Security Support Provider Interface
2002-10-07 20:00:00

WINSTA.dll
0x762d0000
C:\WINDOWS\system32\winsta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Winstation Library
2002-10-07 20:00:00

PROFMAP.dll
0x75890000
C:\WINDOWS\system32\profmap.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Userenv
2002-10-07 20:00:00

NETAPI32.dll
0x71ba0000
C:\WINDOWS\system32\netapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Net Win32 API DLL
2002-10-07 20:00:00

REGAPI.dll
0x76b90000
C:\WINDOWS\system32\regapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Registry Configuration APIs
2002-10-07 20:00:00

WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.1240 (xpsp2.030618-0119)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-07-10 12:22:40

WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2002-10-07 20:00:00

AUTHZ.dll
0x76c90000
C:\WINDOWS\system32\authz.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Authorization Framework
2002-10-07 20:00:00

PSAPI.DLL
0x76bc0000
C:\WINDOWS\system32\psapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Process Status Helper
2002-10-07 20:00:00

VERSION.dll
0x77bd0000
C:\WINDOWS\system32\version.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Version Checking and File Installation Libraries
2002-10-07 20:00:00

SETUPAPI.dll
0x765e0000
C:\WINDOWS\system32\setupapi.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Setup API
2002-10-07 20:00:00

IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2002-10-07 20:00:00
光辉末裔 - 2007-2-15 22:34:00
LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2002-10-07 20:00:00

USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2002-10-07 20:00:00

MSGINA.dll
0x758d0000
C:\WINDOWS\system32\msgina.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Logon GINA DLL
2002-10-07 20:00:00

SHELL32.dll
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1233 (xpsp2.030604-1804)
Microsoft Corporation
Windows Shell Common Dll
2003-06-11 13:48:44

SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\SHLWAPI.DLL
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Shell Light-weight Utility Library
2002-10-07 20:00:00

COMCTL32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2002-10-07 20:00:00

ODBC32.dll
0x900000
C:\WINDOWS\system32\ODBC32.dll
3.520.9041.40
Microsoft Corporation
Microsoft Data Access - ODBC Driver Manager
2003-07-22 11:22:38

comdlg32.dll
0x76320000
C:\WINDOWS\system32\comdlg32.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Common Dialogs DLL
2002-10-07 20:00:00

comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
6.0 (xpsp1.020828-1920)
Microsoft Corporation
User Experience Controls Library
2002-10-07 20:00:00

odbcint.dll
0x1f850000
C:\WINDOWS\system32\odbcint.dll
3.520.7713.0
Microsoft Corporation
Microsoft Data Access - ODBC Resources
2002-10-07 20:00:00

SHSVCS.dll
0x76ba0000
C:\WINDOWS\system32\shsvcs.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Shell Services Dll
2002-10-07 20:00:00

sfc.dll
0x76b80000
C:\WINDOWS\system32\sfc.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows File Protection
2002-10-07 20:00:00
光辉末裔 - 2007-2-15 22:34:00
sfc_os.dll
0x76c30000
C:\WINDOWS\system32\sfc_os.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows 文件保护
2002-10-07 20:00:00

WINTRUST.dll
0x76c00000
C:\WINDOWS\system32\wintrust.dll
5.131.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Trust Verification APIs
2002-10-07 20:00:00

ole32.dll
0x7cab0000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1263 (xpsp2.030819-2129)
Microsoft Corporation
Microsoft OLE for Windows
2003-08-26 04:23:48

IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2002-10-07 20:00:00

msctfime.ime
0xd80000
C:\WINDOWS\system32\MSCTFIME.IME
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Text Frame Work Service IME
2002-10-07 20:00:00

WINSCARD.DLL
0x72360000
C:\WINDOWS\system32\winscard.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Smart Card API
2002-10-07 20:00:00

WTSAPI32.dll
0x76f20000
C:\WINDOWS\system32\wtsapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Terminal Server SDK APIs
2002-10-07 20:00:00

sxs.dll
0x75e00000
C:\WINDOWS\system32\sxs.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Fusion 2.5
2002-10-07 20:00:00

uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2002-10-07 20:00:00

WINMM.dll
0x76b10000
C:\WINDOWS\system32\winmm.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MCI API DLL
2002-10-07 20:00:00

cscdll.dll
0x76570000
C:\WINDOWS\system32\cscdll.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Offline Network Agent
2002-10-07 20:00:00

klogon.dll
0x10000000
C:\WINDOWS\system32\klogon.dll
6.0.0.299
Kaspersky Lab
Logon Visualizer
2006-03-24 19:08:14

OLEAUT32.dll
0x770f0000
C:\WINDOWS\system32\oleaut32.dll
3.50.5016.0
Microsoft Corporation
Microsoft OLE 3.50  for Windows NT(TM) and Windows 95(TM) Operating Systems
2002-10-07 20:00:00

WlNotify.dll
0x758b0000
C:\WINDOWS\system32\wlnotify.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Common DLL to receive Winlogon notifications
2002-10-07 20:00:00
两个铁球 - 2007-2-15 22:34:00
我真服了楼主!又是卡巴Av6,又是瑞星,能够不冲突?
这么武装,怎么还是中毒?不过你很幸运,这时还可肯定自己的系统有毒。而俺此时感到系统有异,却无法确定是否中了,你说烦不烦?(我的也是AV6,主动防御有时报有个svchost.exe失去了完整性,点否无法上网,点允许有心下怀疑,安全软件,包刮这里热门的各种工具却查不出迹象。郁闷啊


呵呵。。。<\??\D:\PROGRA~1\KV2006\PProtect.sys><N/A>
好像还有第3杀软?
光辉末裔 - 2007-2-15 22:34:00
WINSPOOL.DRV
0x72f70000
C:\WINDOWS\system32\winspool.drv
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows Spooler Driver
2002-10-07 20:00:00

MPR.dll
0x71a90000
C:\WINDOWS\system32\mpr.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Multiple Provider Router DLL
2002-10-07 20:00:00

rsaenh.dll
0xffd0000
C:\WINDOWS\system32\rsaenh.dll
5.1.2600.1029 (xpsp1.020426-1800)
Microsoft Corporation
Microsoft Base Cryptographic Provider
2002-10-07 20:00:00

asycfilt.dll
0x70e20000
C:\WINDOWS\system32\asycfilt.dll
3.50.5014
Microsoft Corporation

2002-10-07 20:00:00

SAMLIB.dll
0x71b70000
C:\WINDOWS\system32\samlib.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
SAM Library DLL
2002-10-07 20:00:00

cscui.dll
0x76590000
C:\WINDOWS\system32\cscui.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Client Side Caching UI
2002-10-07 20:00:00

NTMARTA.DLL
0x76cb0000
C:\WINDOWS\system32\ntmarta.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT MARTA provider
2002-10-07 20:00:00

WLDAP32.dll
0x76f30000
C:\WINDOWS\system32\wldap32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Win32 LDAP API DLL
2002-10-07 20:00:00

msv1_0.dll
0x76ce0000
C:\WINDOWS\system32\msv1_0.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Authentication Package v1.0
2002-10-07 20:00:00

wdmaud.drv
0x72c90000
C:\WINDOWS\system32\wdmaud.drv
5.1.2600.0 (XPClient.010817-1148)
Microsoft Corporation
WDM Audio driver mapper
2002-10-07 20:00:00

msacm32.drv
0x72c80000
C:\WINDOWS\system32\msacm32.drv
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft Sound Mapper
2002-10-07 20:00:00

MSACM32.dll
0x77bb0000
C:\WINDOWS\system32\msacm32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft ACM Audio Filter
2002-10-07 20:00:00

midimap.dll
0x77ba0000
C:\WINDOWS\system32\midimap.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Microsoft MIDI Mapper
2002-10-07 20:00:00
光辉末裔 - 2007-2-15 22:35:00
COMRes.dll
0x77020000
C:\WINDOWS\system32\comres.dll
2001.12.4414.42
Microsoft Corporation

2002-10-07 20:00:00

CLBCATQ.DLL
0x76fa0000
C:\WINDOWS\system32\clbcatq.dll
2001.12.4414.42
Microsoft Corporation

2007-02-14 22:18:23

几乎每个系统进程都包括这两个模块

C:\WINDOWS\system32\comres.dll
C:\WINDOWS\system32\clbcatq.dll
光辉末裔 - 2007-2-15 22:40:00
【回复“两个铁球”的帖子】
9楼的兄弟,末有办法啊,有时候就是瑞星查不出来,我还以为是它还没更新库呢,就下了个卡巴,结果更新不了,可能冲突了,瑞星的监控都禁用了。
光辉末裔 - 2007-2-15 22:46:00
怎么有个这个www.my123.com东东,是不是MY123的病毒啊
两个铁球 - 2007-2-15 22:52:00
[Pnpnt / Pnpnt][Running/Boot Start]
<\SystemRoot\System32\Drivers\pnpnt.sys><N/A>

什么的驱动?即插即用的?

{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A> 什么插件?应该卸掉吧?

别的的粗略看来不见异常。
冰刀装不上是因为与那么多杀软间没设置好?但能会让卡巴和瑞星和平相处的人,不致对付不了冰刀的问题啊。看来还是等着高手的指点,俺学习了。
UFO不幸外人 - 2007-2-15 22:55:00
不行了
两个铁球 - 2007-2-15 22:56:00
E:\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[E:\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[E:\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
[E:\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[E:\prkernel.ppl] [Kaspersky Lab, 6.0.0.299]
[e:\params.ppl] [Kaspersky Lab, 6.0.0.299]
[e:\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
[e:\tempfile.ppl] [Kaspersky Lab, 6.0.0.299

刚才只看了每一项的尾,但这些插入是卡巴的吗?待我把自己的扫一份对照看看。


没有!!!我刚才对自己的系统扫了一份SREng日志,基本没有插入。
当然也许是其它安全软件配置造成有差异?卡巴版本有差异?(我的是6.0.0.300)
我不用卡卡助手,无法看到插不插。你的日志里主要还是插在卡卡的进程里。也许确定是卡巴的一些模块?
光辉末裔 - 2007-2-15 22:59:00
【回复“两个铁球”的帖子】
末有办法,这不是病急乱投医吗
witchice - 2007-2-15 23:01:00
我也中了,杀毒中。。。
光辉末裔 - 2007-2-15 23:05:00
好啊,我的卡巴avp.exe里也有C:\WINDOWS\system32\comres.dll
C:\WINDOWS\system32\clbcatq.dll
两个东西



用unlock删除clbcatq.dll就会重启
光辉末裔 - 2007-2-15 23:06:00
【回复“witchice”的帖子】
杀了告诉我怎么杀的,现等.......
1
查看完整版本: 病毒很生气,后果很严重!!