瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】如何用Procexp和Autoruns工具识别与删除木马程序

«1011121314151617»   14  /  23  页   跳转

【原创】如何用Procexp和Autoruns工具识别与删除木马程序

学习
gototop
 

长见识了
gototop
 

这是我单位电脑 的扫描日志,电脑没什么问题,只是想试一下这个软件,帮忙看一下有什么不妥的地方(扫描的时候我在用传奇的脱机外挂,这个是有木马的,不过用了很久,帐号都没问题)

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exec:\windows\system32\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ CnsMin3721北京三七二一科技有限公司c:\windows\downloaded program files\cnsmin.dll

+ explorer.exec:\windows\system32\explorer.exe

+ MicrosoftUpdatesFile not found: C:\WINDOWS\Downloaded Program Files\#.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.d:\瑞星\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.d:\瑞星\rising\rav\ravtimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedd:\瑞星\rising\rfw\rfwmain.exe

+ rxc:\windows\rundll32.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

+ yassistseAssistSettingYahoo!c:\program files\yahoo!\assistant\yassistse.exe

+ YLive.exeYLive c:\program files\yahoo!\assistant\ylive.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ DrvMon.exeDrive MonitorAlcor Micro, Corp.c:\windows\system32\drvmon.exe

HKLM\System\CurrentControlSet\Services

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedd:\瑞星\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterrisingd:\瑞星\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.d:\瑞星\rising\rav\ravmond.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ cnshook.dll3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.d:\repaly\rpshell.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

+ Yahoo!PhotoyPhtbYahoo! Chinac:\program files\yahoo!\assistant\assist\yphtb.dll

+ 粉碎文件Wiper 动态链接库c:\program files\yahoo!\assistant\assist\ywiper.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ AntiFish Classyangling.dllYahoo.c:\program files\yahoo!\assistant\assist\yangling.dll

+ bho Class万能五笔接口程序深圳世强软件开发部c:\program files\common files\wnwb\wnwbio.dll

+ CnsHook Class3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll

+ DragSearch BHODragSearchc:\program files\yahoo!\assistant\assist\ydragsearch.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\qq\qqiehelper.dll

+ Yahoo!PhotoyPhtbYahoo! Chinac:\program files\yahoo!\assistant\assist\yphtb.dll

+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ coolbarToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll

+ ietoolbarCopysoIE搜索工具条: CopysoIE.dll深圳世强软件开发部 www.CopySo.com c:\program files\copyso\copysoie.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ whatever..CopysoIE搜索工具条: CopysoIE.dll深圳世强软件开发部 www.CopySo.com c:\program files\copyso\copysoie.dll

+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ @shdoclc.dll,-864c:\windows\web\related.htm

+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1

+ 清理上网记录File not found: http://assistant.3721.com/clean1.htm?fb=Cns

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 手机短信File not found: http://sms.3721.com/ie/index.htm

+ 腾讯QQQQTENCENTd:\qq\qq.exe

+ 修复浏览器File not found: http://assistant.3721.com/security1.htm?fb=Cns

+ 寻宝乐趣多File not found: http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138

+ 雅虎助手File not found: http://cn.zs.yahoo.com/?source=Cns

gototop
 

晚上回去了把家里的电脑扫描了发上来,请楼主帮忙看一下问题在哪里
gototop
 

这个帖子应该置顶的
gototop
 

【回复“dwhlll”的帖子】
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exec:\windows\system32\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ Explorer.exec:\windows\system32\explorer.exe

有问题。
试试:
删除这两启动项
用卡卡助手结束explorer.exe进程(看清路径)
进安全模式删除C:\windows\system32\explorer.exe

gototop
 

引用:
【七彩黄花菜萱草的贴子】【回复“dwhlll”的帖子】
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exec:\windows\system32\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ Explorer.exec:\windows\system32\explorer.exe

有问题。
试试:
删除这两启动项
用卡卡助手结束explorer.exe进程(看清路径)
进安全模式删除C:\windows\system32\explorer.exe


...........................


补充一点:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exec:\windows\system32\explorer.exe

不能直接删除,要在注册表中把对应项c:\windows\system32\explorer.exe
改为c:\windows\explorer.exe

gototop
 

“dwhlll”朋友,请按楼主在135楼说的处理。
gototop
 

gototop
 

引用:
【BlackStone的贴子】

补充一点:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exec:\windows\system32\explorer.exe

不能直接删除,要在注册表中把对应项c:\windows\system32\explorer.exe
改为c:\windows\explorer.exe


...........................


谢谢,能说一下怎么在注册表中修改吗?我不会
gototop
 
«1011121314151617»   14  /  23  页   跳转
页面顶部
Powered by Discuz!NT