瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 [求助]恼火的Windows 木马启动项:localsystem如何删除

12   2  /  2  页   跳转

[求助]恼火的Windows 木马启动项:localsystem如何删除

[PID: 1528][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1644][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1732][F:\Rising\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [F:\Rising\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [F:\Rising\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1864][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 668][C:\Program Files\Executive Software\Diskeeper\DkService.exe]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\DkLib.dll]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\Tab.dll]  <Executive Software International, Inc.><1.0.31.0>
    [C:\Program Files\Executive Software\Diskeeper\GetFATExtents.dll]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\2052\DkRes.dll]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\DkTabProvider.dll]  <Executive Software International, Inc.><9.0.524.0>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
[PID: 944][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.01.4351>
[PID: 1032][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 1184][f:\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe]  <Rocket Division Software><2.6.1 Build 0x20050401>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
[PID: 368][F:\Rising\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [F:\Rising\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\Rising\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [F:\Rising\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\Rising\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 468][F:\Rising\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [F:\Rising\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [F:\Rising\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [F:\Rising\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [F:\Rising\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\Rising\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\Rising\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [F:\Rising\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 308][C:\Program Files\Huawei-3Com\H3C 802.1X 客户端\Dot1XClient.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\W32N50.dll]  <Printing Communications Assoc., Inc. (PCAUSA)><5.03.16.56>
[PID: 1220][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1216][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\System32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1436][C:\WINDOWS\system\svchost.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
[PID: 2980][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 2300][F:\木马杀客\木马杀客\mmsk.exe]  <木马杀客><2,0,0,6>
    [F:\木马杀客\木马杀客\krnln.fnr]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [F:\木马杀客\木马杀客\HtmlView.fne]  <><1, 0, 0, 1>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
    [F:\木马杀客\木马杀客\iext.fnr]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\TrayIcon.fne]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\iext2.fne]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\iext3.fne]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\xplib.fne]  <N/A><N/A>
    [F:\木马杀客\木马杀客\shell.fne]  <N/A><N/A>
    [F:\木马杀客\木马杀客\dp1.fne]  <N/A><N/A>
    [F:\木马杀客\木马杀客\eAPI.fne]  <><1, 0, 0, 1>
[PID: 3280][F:\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 3904][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\KakaTool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [f:\Tuotu\TuoTuHelper2.dll]  <N/A><2.0.0.4>
    [F:\酷狗3\KuGoo3\KuGoo3DownXControl.ocx]  <N/A><N/A>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
gototop
 

[PID: 1448][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [f:\Tuotu\TuoTuHelper2.dll]  <N/A><2.0.0.4>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [F:\酷狗3\KuGoo3\KuGoo3DownXControl.ocx]  <N/A><N/A>
[PID: 1528][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1644][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1732][F:\Rising\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [F:\Rising\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [F:\Rising\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1864][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 668][C:\Program Files\Executive Software\Diskeeper\DkService.exe]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\DkLib.dll]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\Tab.dll]  <Executive Software International, Inc.><1.0.31.0>
    [C:\Program Files\Executive Software\Diskeeper\GetFATExtents.dll]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\2052\DkRes.dll]  <Executive Software International, Inc.><9.0.524.0>
    [C:\Program Files\Executive Software\Diskeeper\DkTabProvider.dll]  <Executive Software International, Inc.><9.0.524.0>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
[PID: 944][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.01.4351>
[PID: 1032][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 1184][f:\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe]  <Rocket Division Software><2.6.1 Build 0x20050401>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
[PID: 368][F:\Rising\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [F:\Rising\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\Rising\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [F:\Rising\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\Rising\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 468][F:\Rising\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [F:\Rising\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [F:\Rising\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [F:\Rising\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [F:\Rising\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [F:\Rising\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [F:\Rising\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [F:\Rising\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 308][C:\Program Files\Huawei-3Com\H3C 802.1X 客户端\Dot1XClient.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\W32N50.dll]  <Printing Communications Assoc., Inc. (PCAUSA)><5.03.16.56>
[PID: 1220][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1216][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\System32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1436][C:\WINDOWS\system\svchost.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
[PID: 2980][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 2300][F:\木马杀客\木马杀客\mmsk.exe]  <木马杀客><2,0,0,6>
    [F:\木马杀客\木马杀客\krnln.fnr]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [F:\木马杀客\木马杀客\HtmlView.fne]  <><1, 0, 0, 1>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
    [F:\木马杀客\木马杀客\iext.fnr]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\TrayIcon.fne]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\iext2.fne]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\iext3.fne]  <><1, 0, 0, 1>
    [F:\木马杀客\木马杀客\xplib.fne]  <N/A><N/A>
    [F:\木马杀客\木马杀客\shell.fne]  <N/A><N/A>
    [F:\木马杀客\木马杀客\dp1.fne]  <N/A><N/A>
    [F:\木马杀客\木马杀客\eAPI.fne]  <><1, 0, 0, 1>
[PID: 3280][F:\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 3904][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\KakaTool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [f:\Tuotu\TuoTuHelper2.dll]  <N/A><2.0.0.4>
    [F:\酷狗3\KuGoo3\KuGoo3DownXControl.ocx]  <N/A><N/A>
    [c:\windows\rsvpsp.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

请到www.27814939.ys168.com,点“我的软件”下载诺顿进程管理器,终止C:\WINDOWS\system\svchost.exe 的进程,注意它的目录,你只终止C:\WINDOWS\system里面的svchost.exe进程。
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\system\svchost.exe
删除
C:\WINDOWS\system\svchost.exe 注意目录,不要删除错。
gototop
 

好长啊
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT