12   2  /  2  页   跳转

我怀疑机子中毒 帮我看下

【回复“我无邪”的帖子】 [E:\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  <Kaspersky Lab><5.0.1.18>
    [E:\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\FSSync.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\ccclient.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\klipc.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\KLUtil.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\rpt.dll]  <Kaspersky Lab><5.0.388.2>
    [E:\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\prloader.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\prkernel.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\prstring.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\pr_srv.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\pr_clnt.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\tempfile.ppl]  <Kaspersky Lab><5.0.388.0>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 2220][D:\新建文件夹\Thunder\Thunder.exe]  <Thunder Networking Technologies,LTD><5.0.6.98>
    [D:\新建文件夹\Thunder\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [D:\新建文件夹\Thunder\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [D:\新建文件夹\Thunder\log4cplus.dll]  <><1, 0, 2, 1>
    [D:\新建文件夹\Thunder\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [D:\新建文件夹\Thunder\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 73>
    [D:\新建文件夹\Thunder\iThunder.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 30>
    [D:\新建文件夹\Thunder\RegisterDll.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 4>
    [E:\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  <Kaspersky Lab><5.0.1.18>
    [E:\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\FSSync.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\ccclient.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\klipc.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\KLUtil.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\rpt.dll]  <Kaspersky Lab><5.0.388.2>
    [E:\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\prloader.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\prkernel.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\prstring.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\pr_srv.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\pr_clnt.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\tempfile.ppl]  <Kaspersky Lab><5.0.388.0>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 2652][C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\mmsk.exe]  <木马杀客><2,0,0,6>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\krnln.fnr]  <><1, 0, 0, 1>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\HtmlView.fne]  <><1, 0, 0, 1>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\iext.fnr]  <><1, 0, 0, 1>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\TrayIcon.fne]  <><1, 0, 0, 1>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\iext2.fne]  <><1, 0, 0, 1>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\iext3.fne]  <><1, 0, 0, 1>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\xplib.fne]  <N/A><N/A>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\shell.fne]  <N/A><N/A>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\dp1.fne]  <N/A><N/A>
    [E:\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  <Kaspersky Lab><5.0.1.18>
    [E:\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll]  <Kaspersky Lab><5.0.388.1>
gototop
 

【回复“我无邪”的帖子】  [E:\Kaspersky Anti-Virus Personal Pro\FSSync.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\ccclient.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\klipc.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\KLUtil.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\rpt.dll]  <Kaspersky Lab><5.0.388.2>
    [E:\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll]  <Kaspersky Lab><5.0.388.1>
    [E:\Kaspersky Anti-Virus Personal Pro\prloader.dll]  <Kaspersky Lab><5.0.388.0>
    [E:\Kaspersky Anti-Virus Personal Pro\prkernel.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\prstring.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\pr_srv.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\pr_clnt.ppl]  <Kaspersky Lab><5.0.388.0>
    [e:\kaspersky anti-virus personal pro\tempfile.ppl]  <Kaspersky Lab><5.0.388.0>
    [C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX01.954\木马杀客\eAPI.fne]  <><1, 0, 0, 1>
[PID: 1784][E:\World of Warcraft\Launcher.exe]  <The9 Limited><1.2.1.33>
    [E:\Kaspersky Anti-Virus Personal Pro\scrchpg.dll]  <Kaspersky Lab><5.0.1.18>
[PID: 3948][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 3164][C:\DOCUME~1\hlleo\LOCALS~1\Temp\Rar$EX00.594\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

日志正常...
木马杀客不建议用..误报率好象也挺高的...
gototop
 

【回复“mopery”的帖子】那用啥好?
gototop
 

引用:
【xianmi的贴子】【回复“mopery”的帖子】那用啥好?
...........................


一个杀软 一个防火墙够了...
gototop
 

用卡巴就很好啊,你可以把卡巴的病毒库设置为使用超级病毒库。这样也能查到很多可疑程序。
关闭所有浏览窗口以及一些不必要的程序
运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
C:\WINDOWS\vchelper.dll
gototop
 

我用瑞星查杀出卡巴查不到的木马程序了。一直用瑞星。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT