12   2  /  2  页   跳转

我电脑中木马了,请高手进来赐教


正在运行的进程
[PID: 580][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 640][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 664][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 708][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 720][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 868][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 948][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1032][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\System32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1100][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1196][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1256][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1332][C:\WINDOWS\System32\SCardSvr.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\System32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1484][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  <Tencent><4, 0, 1, 11>
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  <Tencent><4, 0, 1, 11>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll]  <Kaspersky Lab><5.0.153.1>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll]  <Kaspersky Lab><1.0.153.342>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll]  <Kaspersky Lab><1.0.153.3>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  <Kaspersky Lab><5.0.0.0>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll]  <Kaspersky Lab><5.0.153.0>
[PID: 1612][C:\Program Files\Iparmor\Iparmor.exe]  <N/A><N/A>
    [C:\Program Files\Iparmor\getportlistxp.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Iparmor\socketinit.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  <Tencent><4, 0, 1, 11>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll]  <Kaspersky Lab><1.0.153.342>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll]  <Kaspersky Lab><1.0.153.3>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  <Kaspersky Lab><5.0.0.0>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll]  <Kaspersky Lab><5.0.153.0>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1636][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  <Tencent><4, 0, 1, 11>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1720][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.01.4345>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1792][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  <Analog Devices, Inc.><3, 2, 6, 0>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 1852][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 400][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  <Tencent><4, 0, 1, 11>
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  <Tencent><4, 0, 1, 11>
    [c:\program files\google\googletoolbar1.dll]  <Google Inc.><3, 0, 131, 0>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\WINDOWS\system32\kakatool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 8>
    [C:\WINDOWS\system32\xunleibho_v13.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 48>
    [C:\Program Files\Tencent\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll]  <Kaspersky Lab><1.0.153.342>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll]  <Kaspersky Lab><1.0.153.3>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  <Kaspersky Lab><5.0.0.0>
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll]  <Kaspersky Lab><5.0.153.0>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 1412][F:\tool\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  <Tencent><4, 0, 1, 11>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

没有问题了
可以考虑进入控制面版的添加删除程序中卸载搜搜地址栏搜索(QQ搜索小助手),这个流氓软件
gototop
 

木马已经解决了,重新下你需要用到的插件,
gototop
 

我的电脑出问题了!!!
帖子链接 http://forum.ikaka.com/topic.asp?board=28&artid=8046014
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT