瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 救救我啊!把日志都附上了,在线等解决办法

12   2  /  2  页   跳转

救救我啊!把日志都附上了,在线等解决办法

正在运行的进程
[PID: 356][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 404][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 432][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 480][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 492][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
[PID: 636][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 684][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
[PID: 724][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 740][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
[PID: 780][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
[PID: 852][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
[PID: 868][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\RsStore.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 980][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1080][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1412][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINDOWS\system\svchostsKey.DLL]  <N/A><N/A>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
[PID: 1480][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  <Yahoo!><2, 1, 0, 1038>
    [C:\WINDOWS\system\svchosts.DLL]  <N/A><N/A>
    [C:\WINDOWS\system\svchostsKey.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
    [D:\软件\qq\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[PID: 1560][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1644][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1780][C:\WINDOWS\SOUNDMAN.EXE]  <Avance Logic, Inc.><5, 0, 0, 0>
    [C:\WINDOWS\system\svchostsKey.DLL]  <N/A><N/A>
[PID: 1788][C:\WINDOWS\VM_STI.EXE]  <Vimicro><4, 2, 1225, 6>
    [C:\WINDOWS\system\svchostsKey.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 1796][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\WINDOWS\system\svchostsKey.DLL]  <N/A><N/A>
[PID: 1836][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 17>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\system\svchostsKey.DLL]  <N/A><N/A>
[PID: 1876][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system\svchostsKey.DLL]  <N/A><N/A>
[PID: 392][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
gototop
 

[PID: 1156][C:\Program Files\DrCOM\西华大学用户认证客户端\ishare_user.exe]  <N/A><N/A>
    [C:\Program Files\DrCOM\西华大学用户认证客户端\cw3220.DLL]  <Borland International><2.0>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
[PID: 332][D:\软件\qq\QQ.exe]  <TENCENT><14, 45, 0, 110>
    [D:\软件\qq\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\QQHelperDll.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\BasicCtrlDll.dll]  <Tencent><0, 3, 3, 6>
    [D:\软件\qq\QQAPI.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [D:\软件\qq\LoginCtrl.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\npkcntc.dll]  <INCA Internet Co., Ltd.><2005, 9, 1, 1>
    [D:\软件\qq\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [D:\软件\qq\QQRes.dll]  <tencent><1, 0, 0, 1>
    [D:\软件\qq\QQMainFrame.dll]  <N/A><N/A>
    [D:\软件\qq\CQQApplication.dll]  <N/A><N/A>
    [D:\软件\qq\NewSkin.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\HostingMgr.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\MailSummary.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
    [D:\软件\qq\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [D:\软件\qq\QQSysMsgMng.dll]  <N/A><N/A>
    [D:\软件\qq\QQGroupMng.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\QQAllInOne.dll]  <N/A><N/A>
    [D:\软件\qq\CameraDll.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\SCCore.dll]  <N/A><N/A>
    [D:\软件\qq\QQCustomFace.dll]  <N/A><N/A>
    [D:\软件\qq\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\QRingMng.dll]  <N/A><N/A>
    [D:\软件\qq\PhoneAPI.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [D:\软件\qq\LongConnection.dll]  <tencent><0, 3, 3, 8>
    [D:\软件\qq\QQAvatar.dll]  <N/A><N/A>
    [D:\软件\qq\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [D:\软件\qq\QQPlugin.dll]  <N/A><N/A>
    [D:\软件\qq\QQPet.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [D:\软件\qq\BQQApplication.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [D:\软件\qq\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [D:\软件\qq\CommercesMng.dll]  <><1, 0, 0, 1>
    [D:\软件\qq\QQUdpGetFileLib.dll]  <tencent><0, 2, 2, 3>
    [D:\软件\qq\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><4, 0, 200, 32>
    [D:\软件\qq\GroupConnection.dll]  <Tencent><0, 3, 3, 5>
    [D:\软件\qq\QQSceneMng.dll]  <N/A><N/A>
    [D:\软件\qq\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 2, 21>
    [D:\软件\qq\videodevice.dll]  <Tencent><1.5.0.0>
    [D:\软件\qq\inplus.dll]  <Tencent><1.5.0.0>
    [C:\WINDOWS\system32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
    [D:\软件\qq\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
[PID: 1752][D:\软件\qq\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [D:\软件\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 1436][D:\软件\qq\qqpet\qqpet.exe]  <腾讯公司><2, 33, 200, 47>
    [D:\软件\qq\qqpet\QQPetResDownload.dll]  <><5, 3, 200, 47>
    [D:\软件\qq\qqpet\QQPetCommunity.dll]  <><5, 3, 200, 47>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 3652][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
    [D:\软件\qq\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 3608][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 3640][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.578\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\system32\TcpIpDog1.dll]  <N/A><N/A>

==================================
文件关联
.TXT  Error. [NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\TcpIpDog1.dll(N/A, N/A)
MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\system32\TcpIpDog1.dll(N/A, N/A)
MSAFD Tcpip [RAW/IP]
    C:\WINDOWS\system32\TcpIpDog1.dll(N/A, N/A)
RSVP UDP Service Provider
    C:\WINDOWS\system32\TcpIpDogR0.dll(N/A, N/A)
RSVP TCP Service Provider
    C:\WINDOWS\system32\TcpIpDogR0.dll(N/A, N/A)

==================================
gototop
 

【回复“xiaohaka”的帖子】
开始--控制面板--性能和维护--管理工具--服务
禁用[Remote Registry Protects / investors]

开始--运行
输入regedit
确定
进入注册表
展开[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
找到后删除investors文件夹

=============

开始--运行
输入regedit
确定
进入注册表
删除如下项:
[NaviHelperObj Class]
{3E422F49-1566-40D3-B43D-077EF739AC32} <C:\WINDOWS\NaviHelper.dll, N/A>

==============

http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载后打开IceSword
在工具栏中点击--文件--设置
勾选“禁止进线程创建”
然后结束如下进程:
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe

删除
C:\WINDOWS\system\svchosts.DLL
C:\WINDOWS\system\svchostsKey.DLL
C:\WINDOWS\system\svchosts.exe
C:\WINDOWS\system\svchosts_hook.DLL(若能找到这个文件就删除)
C:\WINDOWS\NaviHelper.dll

删除完毕
把IceSword的“禁止进线程创建”前的勾去掉

提示:
这一步操作使用IceSword来完成

================

提示:
上述所有操作建议全部使用IceSword来完成
gototop
 

C:\WINDOWS\system\svchosts_hook.DLL(若能找到这个文件就删除)
C:\WINDOWS\NaviHelper.dll
在两个没有找到
gototop
 

引用:
【xiaohaka的贴子】C:\WINDOWS\system\svchosts_hook.DLL(若能找到这个文件就删除)
C:\WINDOWS\NaviHelper.dll
在两个没有找到
...........................

【提示】
若正常模式下无法解决
建议进入安全模式下操作

【小常识】
若文件找不到或无法删除文件
建议进入安全模式下删除
打开我的电脑
在工具栏中点击--工具--文件夹选项--查看
勾选“显示所有文件及文件夹”
同时把“隐藏受保护的操作系统文件(推荐)”前的勾去掉
然后再进行查找一下

或利用KILLBOX来删除
KILLBOX下载:
http://forum.ikaka.com/topic.asp?board=28&artid=6979213

或利用费尔木马强力清除助手来删除
费尔木马强力清除助手使用参考:
http://www.xfilt.com/tech/trojan-horse.htm
gototop
 

非常感谢不言放弃对我的帮助,按照你的方法(有两个文件我没有找到,可能是自己笨很了吧),现在已经没有查到病毒了,万分的感谢你不言放弃。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT