12   2  /  2  页   跳转

求助Trojan.DL.Small.ifr天天有

正在运行的进程
[PID: 572][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 628][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 652][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 696][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 708][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 876][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 940][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1036][D:\瑞星个人防火墙\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1080][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1208][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1328][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1368][D:\瑞星个人防火墙\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [D:\瑞星个人防火墙\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\瑞星个人防火墙\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\瑞星个人防火墙\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\瑞星个人防火墙\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\瑞星个人防火墙\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\瑞星个人防火墙\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [D:\瑞星个人防火墙\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [D:\瑞星个人防火墙\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [D:\瑞星个人防火墙\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\瑞星个人防火墙\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\瑞星个人防火墙\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\瑞星个人防火墙\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [D:\瑞星个人防火墙\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [D:\瑞星个人防火墙\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\瑞星个人防火墙\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [D:\瑞星个人防火墙\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [D:\瑞星个人防火墙\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [D:\瑞星个人防火墙\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [D:\瑞星个人防火墙\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [D:\瑞星个人防火墙\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [D:\瑞星个人防火墙\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\瑞星个人防火墙\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [D:\瑞星个人防火墙\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [D:\瑞星个人防火墙\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [D:\瑞星个人防火墙\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [D:\瑞星个人防火墙\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [D:\瑞星个人防火墙\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1456][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL]  <><1, 2, 0, 2>
    [C:\WINDOWS\SYSTEM32\stdup.dll]  <><3, 2, 1, 6>
    [C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX]  <N/A><N/A>
    [C:\WINDOWS\system32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.7189>
    [C:\WINDOWS\system32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.7189>
    [C:\WINDOWS\system32\igfxpph.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\nvshell.dll]  <NVIDIA Corporation><6.14.10.10040>
    [C:\Program Files\Common Files\Adobe\Shell\PSICON.DLL]  <Adobe Systems, Incorporated><7.0>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 1480][D:\瑞星个人防火墙\Rising\Rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [D:\瑞星个人防火墙\Rising\Rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 12>
    [D:\瑞星个人防火墙\Rising\Rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [D:\瑞星个人防火墙\Rising\Rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [D:\瑞星个人防火墙\Rising\Rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [D:\瑞星个人防火墙\Rising\Rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1728][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1828][D:\瑞星个人防火墙\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [D:\瑞星个人防火墙\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\瑞星个人防火墙\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 2016][D:\瑞星个人防火墙\Rising\Rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 48>
    [D:\瑞星个人防火墙\Rising\Rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [D:\瑞星个人防火墙\Rising\Rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\瑞星个人防火墙\Rising\Rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 196][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.1622>
[PID: 212][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.0.29>
[PID: 276][C:\WINDOWS\system32\hkcmd.exe]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3,0,0,2104>
gototop
 

[C:\WINDOWS\system32\igfxhk.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3,0,0,2104>
[PID: 332][D:\瑞星个人防火墙\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [D:\瑞星个人防火墙\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\瑞星个人防火墙\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\瑞星个人防火墙\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\瑞星个人防火墙\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 400][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 460][D:\瑞星个人防火墙\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 17>
    [D:\瑞星个人防火墙\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [D:\瑞星个人防火墙\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\瑞星个人防火墙\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\瑞星个人防火墙\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\瑞星个人防火墙\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\瑞星个人防火墙\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\瑞星个人防火墙\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 1412][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\STDSVER.DLL]  <><3, 2, 1, 6>
[PID: 1628][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2624][C:\Program Files\Tencent\TT\TTraveler.exe]  <腾讯公司><3.0.0.250>
    [C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 3>
    [C:\Program Files\Tencent\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [D:\瑞星个人防火墙\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  <腾讯公司><1, 1, 0, 5>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 3600][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\SYSTEM32\stdup.dll]  <><3, 2, 1, 6>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
[PID: 2208][C:\Program Files\Common Files\Real\Update_OB\realevent.exe]  <RealNetworks, Inc.><0.1.0.1622>
    [C:\WINDOWS\system32\PNCRT.dll]  <Real Networks, Inc><6.0.0.0>
    [C:\Program Files\Common Files\Real\Update_OB\rnms3270.dll]  <RealNetworks, Inc.><7.0.0.1452>
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  <RealNetworks, Inc.><0.1.0.3389>
    [C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll]  <RealNetworks, Inc.><0.1.0.1760>
    [C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll]  <RealNetworks, Inc.><0.1.0.1622>
    [C:\Program Files\Common Files\Real\Update_OB\rnqu3270.dll]  <RealNetworks, Inc.><7.0.0.1685>
    [C:\Program Files\Common Files\Real\Update_OB\setu3270.dll]  <RealNetworks, Inc.><7.0.0.2311>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
    [C:\Program Files\Common Files\Real\Plugins\http3260.dll]  <RealNetworks, Inc.><6.0.7.4278>
[PID: 1164][D:\System Repair Engineer 2.0.12.350 RC1版\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\Herosoft\HeroV8\VCvtShell.dll]  <herosoft><1, 0, 0, 1>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

大虾们帮看看有什么问题?
gototop
 

顺便问一下,C:\Documents and Settings\Administrator\Local Settings\Temp
里的文件可以删除吗我发现里面有很多垃圾
不知道什么时候弄的江民也在里面  好几年前就删了  现在怎么会在这个文件里出现啊

在线等回复

谢谢各位大虾了
gototop
 

进入控制面版的添加删除程序中卸载Winstdup,MMSASS彩信
如果无法卸载或没有卸载项
建议你下载超级兔子。
下载超级兔子http://dl.pconline.com.cn/html_2/1/75/id=273&pn=0.html
安装好后,打开“超级兔子优化王”“专业卸载,卸载

运行System Repair Engineer,点“启动项目,服务,勾选“隐藏微软服务”选中病毒服务StdService,WinkldUP选择“删除所选服务”“否”最后重启。(每一个逗号隔开的就是一个病毒的服务,请逐一删除)
关闭所有浏览窗口以及一些不必要的程序
运行System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。如果有的话。
MMSAssist]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL, >
[std software]
{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} <C:\WINDOWS\SYSTEM32\stdup.dll, >
[ >> 彩信发送 <<]
<res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm, N/A>
双击我的电脑--工具---文件夹选项--查看选项卡--单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
(请按上述步骤操作,不要略过)
然后找到如下文件并删除(如果有的话)
C:\WINDOWS\system32\STDSVER.DLL
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp可以清空里面所有文件。
C:\PROGRA~1\MMSASS
C:\WINDOWS\SYSTEM32\stdup.dll
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT