瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】求助,高手来帮帮````感激不尽````

12   2  /  2  页   跳转

【原创】求助,高手来帮帮````感激不尽````


[PID: 3868][E:\Program Files\Tencent\QQ\qqpet\qqpet.exe]  <腾讯公司><2, 38, 101, 55>
    [E:\Program Files\Tencent\QQ\qqpet\QQPetResDownload.dll]  <><6, 1, 101, 55>
    [E:\Program Files\Tencent\QQ\qqpet\QQPetCommunity.dll]  <><6, 1, 101, 55>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [d:\Program Files\rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 2640][G:\下载文件\最新木马\QQPetNurse.exe]  <永恒E网><2.1.1.3>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [d:\Program Files\rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 3220][E:\Program Files\Tencent\TT\TTraveler.exe]  <腾讯公司><3.0.0.250>
    [E:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  <腾讯公司><1, 1, 0, 5>
    [E:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 3>
    [E:\Program Files\Tencent\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [d:\Program Files\rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\icm32.dll]  <Microsoft Corporation><5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)>
    [C:\WINDOWS\system32\WNWBIO.IME]  <深圳世强软件开发部 www.wnwb.com ><2005, 1, 31, 1>
[PID: 2004][E:\Program Files\Tencent\QQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [E:\Program Files\Tencent\QQ\CoralAssist.DLL]  <N/A><4.0.0 Build 20051112>
    [E:\Program Files\Tencent\QQ\CoralQQ.DLL]  <Coral Team><4.2.2 Build 20060318>
    [E:\Program Files\Tencent\QQ\IPSearcher.dll]  <N/A><1.0.0.4>
    [E:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 14>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [E:\Program Files\Tencent\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [e:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [E:\Program Files\Tencent\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2005, 9, 1, 1>
    [E:\Program Files\Tencent\QQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [E:\Program Files\Tencent\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQMainFrame.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\CQQApplication.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\MailSummary.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQPlugin.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQAllInOne.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\SCCore.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQCustomFace.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [E:\Program Files\Tencent\QQ\QQAvatar.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QRingMng.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [E:\Program Files\Tencent\QQ\LongConnection.dll]  <tencent><5, 0, 201, 14>
    [E:\Program Files\Tencent\QQ\BQQApplication.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [E:\Program Files\Tencent\QQ\QQMagicFace.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQSceneMng.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\GroupConnection.dll]  <Tencent><5, 0, 202, 30>
    [E:\Program Files\Tencent\QQ\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [E:\Program Files\Tencent\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
gototop
 

[E:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  <N/A><N/A>
[PID: 480][E:\Program Files\Tencent\QQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [E:\Program Files\Tencent\QQ\CoralAssist.DLL]  <N/A><4.0.0 Build 20051112>
    [E:\Program Files\Tencent\QQ\CoralQQ.DLL]  <Coral Team><4.2.2 Build 20060318>
    [E:\Program Files\Tencent\QQ\IPSearcher.dll]  <N/A><1.0.0.4>
    [E:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 14>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [E:\Program Files\Tencent\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [e:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [E:\Program Files\Tencent\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2005, 9, 1, 1>
    [E:\Program Files\Tencent\QQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [E:\Program Files\Tencent\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQMainFrame.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\CQQApplication.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\MailSummary.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQPlugin.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [E:\Program Files\Tencent\QQ\QQAvatar.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QRingMng.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [E:\Program Files\Tencent\QQ\LongConnection.dll]  <tencent><5, 0, 201, 14>
    [E:\Program Files\Tencent\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\BQQApplication.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [E:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 140>
    [E:\Program Files\Tencent\QQ\QQSceneMng.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 3, 30>
[PID: 3544][E:\Program Files\Tencent\QQ\qqpet\qqpet.exe]  <腾讯公司><2, 38, 101, 55>
    [E:\Program Files\Tencent\QQ\qqpet\QQPetResDownload.dll]  <><6, 1, 101, 55>
    [E:\Program Files\Tencent\QQ\qqpet\QQPetCommunity.dll]  <><6, 1, 101, 55>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [d:\Program Files\rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 3356][D:\Program Files\Corel\Graphics9\Programs\coreldrw.exe]  <Corel Corporation><9.397>
    [D:\Program Files\Corel\Graphics9\Programs\CrlWeb91.dll]  <><1, 0, 0, 1>
    [D:\Program Files\Corel\Graphics9\Programs\CRLCTL91.dll]  <Corel Corporation><9.397>
    [D:\Program Files\Corel\Graphics9\Programs\CRLUI91.dll]  <Corel Corporation><9.397>
    [D:\Program Files\Corel\Graphics9\Programs\CRLIUI91.dll]  <Corel Corporation><9.397>
    [D:\Program Files\Corel\Graphics9\Programs\FN3API.dll]  <Bitstream, Inc.><3, 0, 0, 2>
    [C:\WINDOWS\system32\SHW32.dll]  <N/A><N/A>
    [D:\Program Files\Corel\Graphics9\Programs\ixlacam.dll]  <IXLA Limited><1, 5, 0, 0>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [D:\Program Files\Corel\Graphics9\Programs\iuiintl.dll]  <Corel Corporation><9.397>
    [C:\WINDOWS\system32\ATMLIB.dll]  <Adobe Systems><5.1 Build 226>
    [D:\Program Files\Corel\Graphics9\Programs\drawintl.dll]  <Corel Corporation><9.397>
    [d:\Program Files\Corel\Graphics9\Programs\Sprof32.dll]  <Eastman Kodak Company><1.6.1>
    [D:\Program Files\Corel\Graphics9\Programs\KPSYS32.dll]  <Eastman Kodak Company><3.2.2>
    [D:\Program Files\Corel\Graphics9\Programs\KPCP32.dll]  <Eastman Kodak Company><3.1.0>
    [d:\Program Files\Corel\Graphics9\Programs\CDRCPR91.DLL]  <Corel Corporation><9.337>
    [d:\Program Files\Corel\Graphics9\Filters\IECDR91.FLT]  <Corel Corporation><9.397>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNL4EUI.DLL]  <CANON INC.><5.02>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNL4E.DLL]  <CANON INC.><5.02>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNL4EGR.DLL]  <CANON INC.><5.02>
    [C:\WINDOWS\system32\JPWB.IME]  <长江软件工作室><4.00.950>
    [C:\WINDOWS\system32\WNWBIO.IME]  <深圳世强软件开发部 www.wnwb.com ><2005, 1, 31, 1>
    [d:\Program Files\Corel\Graphics9\Filters\IEPSD91.FLT]  <Corel Corporation><9.397>
    [d:\Program Files\Corel\Graphics9\Filters\IECPT91.FLT]  <Corel Corporation><9.397>
[PID: 772][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
gototop
 

[C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 3064][C:\Program Files\racer-henan-cnc\RacerKp.exe]  <北京润汇科技有限公司><1, 0, 0, 1>
[PID: 1520][D:\Program Files\TTPlayer\TTPlayer.exe]  <N/A><4, 6, 7, 0>
    [D:\Program Files\TTPlayer\ttpcomm.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [D:\Program Files\TTPlayer\ttpres.dll]  <N/A><4, 6, 7, 0>
    [D:\Program Files\TTPlayer\AddIn\ttp_asf.dll]  <N/A><N/A>
    [D:\Program Files\TTPlayer\AddIn\ttp_aac.dll]  <N/A><N/A>
    [D:\Program Files\TTPlayer\AddIn\ttp_ac3dts.dll]  <N/A><N/A>
[PID: 3256][C:\DOCUME~1\毛伟\LOCALS~1\Temp\101608.exe]  <1000 Oaks><1, 0, 2, 0>
[PID: 3608][D:\Program Files\Adobe\Photoshop CS\Photoshop.exe]  <Adobe Systems, Incorporated><8.0.1 (8.0x125)>
    [D:\Program Files\Adobe\Photoshop CS\UID.mr.dll]  <Adobe Systems, Inc.><1, 1, 0, 0>
    [D:\Program Files\Adobe\Photoshop CS\AWSCommonUI.dll]  <Adobe Systems, Incorporated><3.0.0.432>
    [D:\Program Files\Adobe\Photoshop CS\AWSSCL.dll]  <Adobe Systems><4.0.0.34>
    [D:\Program Files\Adobe\Photoshop CS\WebAccessUtils.dll]  <Adobe Systems, Incorporated><3.0.0.432>
    [D:\Program Files\Adobe\Photoshop CS\BIBUtils.dll]  <Adobe Systems Incorporated><1.00.0>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [D:\Program Files\Adobe\Photoshop CS\Photoshop.dll]  <N/A><N/A>
    [D:\Program Files\Adobe\Photoshop CS\PSViews.dll]  <Adobe Systems, Incorporated><8.0.1 (8.0x125)>
    [D:\Program Files\Adobe\Photoshop CS\PSArt.dll]  <Adobe Systems, Incorporated><8.0.1 (8.0x125)>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNL4EUI.DLL]  <CANON INC.><5.02>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNL4E.DLL]  <CANON INC.><5.02>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNL4EGR.DLL]  <CANON INC.><5.02>
    [D:\Program Files\Adobe\Photoshop CS\asn.er.dll]  <Adobe Systems Incorporated><1.51x3, EndUser, Release>
    [D:\Program Files\Adobe\Photoshop CS\增效工具\扩展\FastCore.8BX]  <Adobe Systems, Incorporated><8.0.1 (8.0x126)>
    [D:\Program Files\Adobe\Photoshop CS\PLUGIN.dll]  <Adobe Systems, Incorporated><8.0.1 (8.0x125)>
    [D:\Program Files\Adobe\Photoshop CS\增效工具\扩展\MMXCore.8BX]  <Adobe Systems, Incorporated><8.0.1 (8.0x126)>
    [D:\Program Files\Adobe\Photoshop CS\Required\ADMPlugin.apl]  <Adobe Systems Incorporated><2.84pe69a 02.06.17-00:03:36h>
    [D:\Program Files\Adobe\Photoshop CS\Required\PNGIcons.apl]  <Adobe Systems Incorporated><1.21x7 2001.12.14-1602h.21s>
    [D:\Program Files\Adobe\Photoshop CS\Required\ASDataStream.apl]  <Adobe Systems Incorporated><1.02x7 02.02.15-01:45:06h>
    [D:\Program Files\Adobe\Photoshop CS\增效工具\解析程序\PDF 增效工具.8BI]  <Adobe Systems, Incorporated><8.0.1 (8.0x126)>
    [D:\Program Files\Adobe\Photoshop CS\BIB.dll]  <Adobe Systems Incorporated><1.1.16>
    [D:\Program Files\Adobe\Photoshop CS\JP2KLib.dll]  <Adobe systems Incorporated><1.0.28706>
    [D:\Program Files\Adobe\Photoshop CS\增效工具\文件格式\Camera Raw.8BI]  <Adobe Systems Incorporated><2.0>
gototop
 

[D:\Program Files\Adobe\Photoshop CS\ACE.dll]  <Adobe Systems Incorporated><2.05.16>
    [D:\Program Files\Adobe\Photoshop CS\AGM.dll]  <Adobe Systems Incorporated><4.12.36>
    [D:\Program Files\Adobe\Photoshop CS\CoolType.dll]  <Adobe Systems Incorporated><4.14.20>
    [C:\WINDOWS\system32\ATMLIB.dll]  <Adobe Systems><5.1 Build 226>
    [D:\Program Files\Adobe\Photoshop CS\AWSCommonSymbols.dll]  <Adobe Systems, Incorporated><3.0.0.432>
    [D:\Program Files\Adobe\Photoshop CS\ARM.dll]  <Adobe Systems, Incorporated><3.0.0.432>
    [D:\Program Files\Adobe\Photoshop CS\FileInfo.dll]  <Adobe Systems, Incorporated><3.0.0.432>
    [D:\Program Files\Adobe\Photoshop CS\增效工具\Adobe Photoshop Only\自动\脚本支持.8li]  <Adobe Systems Incorporated><8.0>
    [D:\Program Files\Adobe\Photoshop CS\ExtendScriptIDE.dll]  <Adobe Systems, Incorporated><3.2.21>
    [D:\Program Files\Adobe\Photoshop CS\ExtendScript.dll]  <Adobe Systems, Incorporated><3.2.21>
    [D:\Program Files\Adobe\Photoshop CS\ScCore.dll]  <Adobe Systems, Incorporated><3.2.21>
    [D:\Program Files\Adobe\Photoshop CS\Tw10122.dat]  <Adobe Systems, Incorporated><8.0.1 (8.0x125)>
[PID: 3812][G:\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================

妈呀,太多了,终于完了,麻烦各位了 ``再现守侯``
gototop
 

人呢``??
gototop
 

删除服务
[Indexing Data / lDOMANE]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>

重启后删除文件

C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL


另请参考
[推荐]瑞星升级后出现漏洞攻击的解决办法
http://forum.ikaka.com/topic.asp?board=28&artid=5961295
gototop
 

我前几天有过你说的这种情况,现在宽带连接还是断断续续的,同情你...你也发个日志上来让别人帮你看下吧
gototop
 

11
gototop
 

如果问题还未解决,就重启后再扫份报告粘来。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT