瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 又来了!中木马了!!!大家帮忙啊!!!

12   2  /  2  页   跳转

又来了!中木马了!!!大家帮忙啊!!!

[PID: 1580][C:\WINDOWS\system32\cidaemon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 6068][C:\WINDOWS\system32\cidaemon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 3500][C:\Program Files\NJStar Communicator\Njcom32.exe]  <NJStar Software Corp.><2.60.60318>
    [C:\Program Files\NJStar Communicator\NJTEXT32.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>
    [C:\Program Files\NJStar Communicator\NJDBCS32.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>
    [C:\Program Files\NJStar Communicator\Njhook32.dll]  <NJStar Software Corp.><2, 60, 1, 60308>
    [C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll]  <BackWeb><Version 7.2.0 (Build 157R)>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL]  <Symantec Corporation><2006.2.00.153>
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  <Symantec Corporation><104.0.4.3>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 1, 1018>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 9, 1324>
[PID: 2440][C:\Program Files\NJStar Communicator\NJSIME.EXE]  <NJStar Software Corp.><2.60.60218>
    [C:\Program Files\NJStar Communicator\NJTXTOUT.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>
    [C:\Program Files\NJStar Communicator\NJDBCS.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>
    [C:\Program Files\NJStar Communicator\NJINPUT.dll]  <NJStar Software Corp.><5, 1, 3, 51218>
    [C:\Program Files\NJStar Communicator\NJMail32.dll]  <NJStar Software Corp.><5, 1, 3, 51208>
    [C:\Program Files\NJStar Communicator\NJKBHK32.dll]  <N/A><N/A>
    [C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll]  <BackWeb><Version 7.2.0 (Build 157R)>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL]  <Symantec Corporation><2006.2.00.153>
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  <Symantec Corporation><104.0.4.3>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 1, 1018>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 9, 1324>
    [C:\Program Files\NJStar Communicator\NJIMECHT.DLL]  <NJStar Software Corp.><2.60.60218>
[PID: 5636][C:\Program Files\Messenger\msmsgs.exe]  <Microsoft Corporation><4.7.3001>
    [C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll]  <BackWeb><Version 7.2.0 (Build 157R)>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL]  <Symantec Corporation><2006.2.00.153>
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  <Symantec Corporation><104.0.4.3>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 1, 1018>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 9, 1324>
[PID: 3868][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
    [C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll]  <BackWeb><Version 7.2.0 (Build 157R)>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL]  <Symantec Corporation><2006.2.00.153>
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  <Symantec Corporation><104.0.4.3>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 1, 1018>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 9, 1324>
    [C:\Program Files\NJStar Communicator\Njhook32.dll]  <NJStar Software Corp.><2, 60, 1, 60308>
    [C:\Program Files\NJStar Communicator\NJDBCS32.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>
    [C:\Program Files\NJStar Communicator\NJTEXT32.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>
[PID: 1208][C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\Rar$EX00.890\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\DOCUME~1\KAI~1.82C\LOCALS~1\Temp\IadHide5.dll]  <BackWeb><Version 7.2.0 (Build 157R)>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\ASOEHOOK.DLL]  <Symantec Corporation><2006.2.00.153>
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  <Symantec Corporation><104.0.4.3>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 1, 1018>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 9, 1324>
    [C:\Program Files\NJStar Communicator\Njhook32.dll]  <NJStar Software Corp.><2, 60, 1, 60308>
    [C:\Program Files\NJStar Communicator\NJDBCS32.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>
    [C:\Program Files\NJStar Communicator\NJTEXT32.DLL]  <NJStar Software Corp.><5, 10, 0, 60218>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

我进入安全模式清空了C:\DOCUME~1\KAI~\LOCALS~1\Temp\,然后没有查出任何木马和病毒。再进入普通模式,开机果然没有查到病毒的提示了,这是为什么啊?C:\Documents and Settings\KAI.(我电脑的注册号)\Local Settings\Temporary Internet Files\Temporary Internet Files\Content.IE5\TI0AD10G\Patch[1].exe这个文件找不到也没事了??现在我系统中应该没有Trojan.Dropper了吧?
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT