瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 刚接手的一台文件服务器 发现有病毒 帮忙看看 有日志 在线等
喜欢喝水 - 2007-5-30 9:59:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start>  [奇虎网]
    <vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe>  [(Verified)Symantec Corporation]
    <P2POver><C:\Program Files\NetSoft\P2POver\P2POver.exe>  []
    <UserFaultCheck><%systemroot%\system32\dumprep 0 -u>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <360Safe><Rundll32.exe C:\PROGRA~1\360safe\AntiAdwa.dll,KillAdware>  [360Safe.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <WinVNC4><"C:\Program Files\RealVNC\WINVNC4.EXE" -noconsole -service>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><%SystemRoot%\system32\logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll>  [(Verified)Symantec Corporation]

==================================
启动文件夹
N/A

==================================
服务
[Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
  <"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Intel Alert Handler / Intel Alert Handler][Running/Auto Start]
  <C:\WINDOWS\system32\ams_ii\hndlrsvc.exe><Intel? Corporation>
[Intel Alert Originator / Intel Alert Originator][Running/Auto Start]
  <C:\WINDOWS\system32\ams_ii\iao.exe><Intel? Corporation>
[Intel File Transfer / Intel File Transfer][Running/Auto Start]
  <C:\WINDOWS\system32\cba\xfr.exe><Intel? Corporation>
[Intel PDS / Intel PDS][Running/Auto Start]
  <C:\WINDOWS\system32\cba\pds.exe><Intel? Corporation>
[Symantec System Center Discovery Service / NSCTOP][Running/Auto Start]
  <C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE><Symantec Corporation>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[Serv-U FTP 服务器 / Serv-U][Running/Auto Start]
  <C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe><Rhino Software, Inc. +1(262) 560-9627>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
  <"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>

==================================
驱动程序
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <system32\DRIVERS\ipinip.sys><N/A>
[NAVENG / NAVENG][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070528.019\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070528.019\navex15.sys><Symantec Corporation>
[NetGroup Packet Filter Driver / NPF][Running/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[p2pfilter / p2pfilter][Running/Manual Start]
  <\??\C:\Program Files\NetSoft\P2POver\p2pfilter.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SAVRT / SAVRT][Running/System Start]
  <\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/Auto Start]
  <\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[SNIFFER Protocol Driver / Sniffer][Running/Auto Start]
  <system32\DRIVERS\sniffer.sys><N/A>
[SymEvent / SymEvent][Running/Manual Start]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>

==================================
浏览器加载项
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\program files\chinanet\vnettransfer1.dll, >
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 328][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 396][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 452][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\NavLogon.dll]  [Symantec Corporation, 9.0.0.338]
[PID: 1748][C:\Program Files\360safe\safemon\360Tray.exe]  [奇虎网, 3, 3, 0, 1004]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
    [C:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 2, 0, 1001]
    [C:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 3, 0, 1004]
    [C:\Program Files\360safe\live.dll]  [360safe.COM, 1, 0, 0, 1012]
[PID: 1756][C:\PROGRA~1\SYMANT~1\VPTray.exe]  [Symantec Corporation, 9.0.0.338]
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  [Symantec Corporation, 9.3.0.28]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
    [C:\Program Files\Symantec AntiVirus\Cliscan.dll]  [Symantec Corporation, 9.0.0.338]
    [C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL]  [Symantec Corporation, 9.0.0.338]
    [C:\Program Files\Symantec AntiVirus\Cliproxy.dll]  [Symantec Corporation, 9.0.0.338]
[PID: 1772][C:\Program Files\NetSoft\P2POver\P2POver.exe]  [, 2, 0, 0, 3]
    [C:\WINDOWS\system32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\WINDOWS\system32\pthreadVC.dll]  [N/A, ]
    [C:\WINDOWS\system32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\Program Files\NetSoft\P2POver\DBdll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
[PID: 1812][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
[PID: 948][C:\WINDOWS\system32\MsgSys.EXE]  [Intel? Corporation, 6.12.0.112 E]
    [C:\WINDOWS\system32\NTS.dll]  [Intel? Corporation, 6.12.0.112 E]
    [C:\WINDOWS\system32\CBA.DLL]  [Intel? Corporation, 6.12.0.112 E]
    [C:\WINDOWS\system32\MsgSys.dll]  [Intel? Corporation, 6.12.0.112 E]
    [C:\WINDOWS\system32\PDS.DLL]  [Intel? Corporation, 6.12.0.112 E]
    [C:\WINDOWS\system32\NTSU2T.DLL]  [Intel Corporation, 6.12.0.0000 E]
[PID: 2320][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
    [C:\WINDOWS\system32\wucltui.dll]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
    [C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.374\wups2.dll]  [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
[PID: 3864][C:\Program Files\RhinoSoft.com\Serv-U\ServUAdmin.exe]  [Rhino Software, Inc. +1(262) 560-9627, 6.4.0.2]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
    [C:\Program Files\RhinoSoft.com\Serv-U\libeay32.DLL]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8d]
    [C:\Program Files\RhinoSoft.com\Serv-U\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\RhinoSoft.com\Serv-U\ssleay32.DLL]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8d]
[PID: 2484][C:\Program Files\360safe\360safe.exe]  [奇虎网, 3, 3, 0, 1004]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
    [C:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 3, 0, 1004]
    [C:\Program Files\360safe\AntiEng.dll]  [360Safe.com, 3, 3, 0, 1001]
    [C:\Program Files\360safe\Antispy.dll]  [奇虎网, 3, 3, 0, 1001]
    [C:\Program Files\360safe\LeakCheck.dll]  [360Safe.com, 3, 3, 0, 1002]
    [C:\Program Files\360safe\CleanHis.dll]  [奇虎网, 3, 0, 2, 1000]
    [C:\Program Files\360safe\AntiActi.dll]  [360Safe.com, 2, 0, 0, 3000]
    [C:\Program Files\360safe\live.dll]  [360safe.COM, 1, 0, 0, 1012]
[PID: 1636][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  [Symantec Corporation, 9.0.0.338]
[PID: 4036][C:\Program Files\NetSoft\P2POver\P2POver.exe]  [, 2, 0, 0, 3]
    [C:\WINDOWS\system32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\WINDOWS\system32\pthreadVC.dll]  [N/A, ]
    [C:\WINDOWS\system32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\Program Files\NetSoft\P2POver\DBdll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
[PID: 3668][D:\SRENG\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
    [D:\SRENG\Plugins\NWMON.SRE]  [Smallfrogs Studio, 1, 0, 0, 8]
1
查看完整版本: 刚接手的一台文件服务器 发现有病毒 帮忙看看 有日志 在线等