瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】如何用Procexp和Autoruns工具识别与删除木马程序

«89101112131415»   12  /  23  页   跳转

【原创】如何用Procexp和Autoruns工具识别与删除木马程序

还有我不IE浏览器不能用了
打开后有框,说....加载项遇到故障需要关闭....
我现在用腾讯的了
gototop
 

从日志中未发现异常
去http://forum.ikaka.com/topic.asp?board=28&artid=7386171
把问题在那里描述一下
gototop
 

哦,
1.开机后就会自动出来一个记事本里面有一窜英文.对后面的操作没影响,我想问问是什么意思,怎样消除.
2.IE浏览器打开网址后点击其他联接时会出现一个框:Internet Explorer已经遇到加载项故障并且需要关闭.之后就没法使用了

是不是和病毒有关.怎么修复~~~
gototop
 

1)看机启动后不要关闭那个记事本,用Procexp看看是那个进程运行的Notepad.exe

2)用Autoruns取消IE的插件试试
gototop
 

太复杂了啊
眼都看花了啊
gototop
 

你好!我刚下载了最新版的,不大会用.请帮我看下日志谢谢~
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ KAVPersonal50Kaspersky Anti-Virus GUI Part(Not verified) Kaspersky Labd:\program files\kaspersky anti-virus personal\kav.exe

HKLM\System\CurrentControlSet\Services

+ kavsvcKaspersky Anti-Virus Service(Not verified) Kaspersky Labd:\program files\kaspersky anti-virus personal\kavsvc.exe

+ NVSvcNVIDIA Driver Helper Service, Version 40.72(Not verified) NVIDIA Corporationd:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall Service(Not verified) Beijing Rising Technology Corporation Limitedd:\program files\rising\rfw\rfwsrv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Desktop ExplorerNVIDIA Desktop Explorer, Version 40.72 (Not verified) NVIDIA Corporationd:\windows\system32\nvshell.dll

+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 40.72 (Not verified) NVIDIA Corporationd:\windows\system32\nvshell.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell Extensions(Not verified) RealNetworks, Inc.d:\program files\real\realone player\rpshell.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web 文件夹d:\program files\common files\microsoft shared\web folders\msonsext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch Module(Not verified) Amaze Softd:\program files\flashget\jccatch.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ FlashGetFlashGet(Not verified) Amaze Softd:\program files\flashget\flashget.exe

gototop
 

【回复“阿蛮”的帖子】
日志里看不出有啥问题
你的机子有啥异常嘛
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ nwizNVIDIA nView Wizard, Version 100.43 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe

+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.c:\windows\soundman.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

HKLM\System\CurrentControlSet\Services

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ NVMLCFile not found: C:\WINDOWS\System32\ronvidiat.dll

+ WinMediaRoNVidiaRoNVidiac:\windows\system32\nvbworks.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe

+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

gototop
 

【回复“流浪射手”的帖子】
+ WinMediaRoNVidiaRoNVidiac:\windows\system32\nvbworks.dll

禁用重启试试
gototop
 

13楼是不是有点出入啊?
这句"此工具可以替换window资源管理器,选择Options-Replace Task Manager,则每次启动任务管理器时则启动此程序"红线部份是否应为"任务管理器".
gototop
 
«89101112131415»   12  /  23  页   跳转
页面顶部
Powered by Discuz!NT