瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】如何用Procexp和Autoruns工具识别与删除木马程序

«1112131415161718»   15  /  23  页   跳转

【原创】如何用Procexp和Autoruns工具识别与删除木马程序

这是我里电脑扫描的结果,帮忙看一下

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ CnsMinFile not found: C:\WINDOWS\downlo~1\CnsMin.dll

+ DSLAGENTEXEFile not found: dslagent.exe

+ GSICONEXEFile not found: GSICON.EXE

+ LegendRemDriverc:\program files\legend\联想遥控器驱动\remdrv.exe

+ netbusFile not found: C:\\netbus.exe

+ NvCplDaemonNVIDIA Taskbar Utility LibraryNVIDIA Corporationc:\windows\system32\nvqtwk.dll

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.d:\瑞星\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.d:\瑞星\rising\rav\ravtimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedd:\瑞星\rfw\rfwmain.exe

+ SoundManAvance Sound ManagerAvance Logic, Inc.c:\windows\soundman.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

C:\Documents and Settings\All Users\「开始」菜单\程序\启动

+ 联想键盘驱动程序.lnkSkdaemon Microsoft 基础类应用程序c:\program files\legend\联想标准功能键盘驱动程序安装\skdaemon.exe

C:\WINDOWS\Html

+ 腾讯QQ.lnkQQTENCENTe:\qq\qq.exe

HKLM\System\CurrentControlSet\Services

+ NVSvcNVIDIA Driver Helper Service, Version 15.20NVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedd:\瑞星\rfw\rfwsrv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ cnshook.dll3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

+ 粉碎文件File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ CnsHook Class3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll

+ DragSearch BHOFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司e:\qq\qqiehelper.dll

+ ThunderIEHelper Classxunleibho Modulec:\windows\system32\xunleibho_v5.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ coolbar\

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softe:\网络快车\flashget\flashget.exe

+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1

+ 江民在线杀毒File not found: http://club.jiangmin.com/kvscan/KvOnline.asp

+ 清理上网记录File not found: http://assistant.3721.com/clean1.htm?fb=Cns

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 上网助手File not found: http://assistant.3721.com/index.htm?fb=Cns

+ 手机短信File not found: http://sms.3721.com/ie/index.htm?pid=U_flashget_62580

+ 腾讯QQQQTENCENTe:\qq\qq.exe

+ 修复浏览器File not found: http://assistant.3721.com/security1.htm?fb=Cns

+ 寻宝乐趣多File not found: http://hot.3721.com/rd/shop_btn.htm

+ 易趣购物File not found: http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn

Task Scheduler

+ Symantec NetDetect.jobSymantec NetDetectSymantec Corporationc:\program files\symantec\liveupdate\ndetect.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ skwinlogonc:\windows\system32\dll.dll

+ UpdatenmFile not found: upern.dll

+ xyzDownFile not found: xyzDown.dll

gototop
 

引用:
【dwhlll的贴子】

谢谢,能说一下怎么在注册表中修改吗?我不会
...........................


http://forum.ikaka.com/topic.asp?board=28&artid=7318038&page=2的17楼
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ CnsMinFile not found: C:\WINDOWS\downlo~1\CnsMin.dll
+ DSLAGENTEXEFile not found: dslagent.exe
+ GSICONEXEFile not found: GSICON.EXE
+ netbusFile not found: C:\\netbus.exe

C:\Documents and Settings\All Users\「开始」菜单\程序\启动
C:\WINDOWS\Html

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ coolbar\

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ skwinlogonc:\windows\system32\dll.dll
+ UpdatenmFile not found: upern.dll
+ xyzDownFile not found: xyzDown.dll

删除以上启动项
重启
删除c:\windows\system32\dll.dll试试
gototop
 

引用:
【BlackStone的贴子】

补充一点:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exec:\windows\system32\explorer.exe

不能直接删除,要在注册表中把对应项c:\windows\system32\explorer.exe
改为c:\windows\explorer.exe


...........................



晕,我直接把这一项删除了,在注册表里找不到了
gototop
 

引用:
【dwhlll的贴子】


晕,我直接把这一项删除了,在注册表里找不到了
...........................


没事的
把一下内容保存为reg.reg,双击导入即可。

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="C:\Windows\Explorer.exe"
gototop
 

中了病毒才来学习,呵呵呵
gototop
 

引用:
【BlackStone的贴子】Autoruns版本升级到8.4

增加了遍历驱动的页签项

http://www.sysinternals.com/Utilities/autoruns.html
...........................

谢谢楼主耐心细致的讲解!学习了。
在汉化新世纪已经有Autoruns8.4的汉化版了,我刚下的。有E不好的朋友可以去那里下载
gototop
 

引用:
【一簔烟雨的贴子】
谢谢楼主耐心细致的讲解!学习了。
在汉化新世纪已经有Autoruns8.4的汉化版了,我刚下的。有E不好的朋友可以去那里下载
...........................


autoruns的官方最新版本为8.43
gototop
 

谢谢楼主
gototop
 

楼主强啊
gototop
 
«1112131415161718»   15  /  23  页   跳转
页面顶部
Powered by Discuz!NT