瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】QQ问题和explorer.exe进程问题

12   1  /  2  页   跳转

【求助】QQ问题和explorer.exe进程问题

【求助】QQ问题和explorer.exe进程问题

求助两个问题:
1、我的QQ老是提示在别的地方登陆,被迫下线,我敢保证我的密码只有我一个人知道,我也用瑞星查毒了,没有找到呀,出现那样的事情后,我没有改密码,用原来的密码照样登陆,这是怎么回事?QQ没有被盗。不过我查了一下Q币,我依稀记得很久以前我有10个的,现在好像没有了,请问各位怎么解决啊?

2、我的系统现在出现了这样的问题。有时候会弹出A对话框,接着按确定之后,就出现B对话框,B对话框就像阴魂一样,每个1秒钟就出现一次,无法结束,无奈只能关闭瑞星监控,嗨,这个又怎么解决啊?

附件附件:

下载次数:515
文件类型:image/pjpeg
文件大小:
上传时间:2006-9-10 16:18:53
描述:



最后编辑2006-09-10 21:42:08.577000000
分享到:
gototop
 

中了病毒,或者想了解病毒信息的朋友请加QQ群:3365760(1号群) 22409354(2号群)
gototop
 

我认为你的密码经有第二个人知道
你太武断了
建议修改密码
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
gototop
 

B图 通过...

A图..
开始-运行-CMD
输入
for %1 in (%windir%\system32\*.dll) do regsvr32.exe /s %1

看看能否解决..
gototop
 

【回复“曾强”的帖子】
建议:贴SREng日志看看。
估计系统中可能有插explorer.exe的木马。
gototop
 

引用:
【mopery的贴子】B图 通过...

A图..
开始-运行-CMD
输入
for %1 in (%windir%\system32\*.dll) do regsvr32.exe /s %1

看看能否解决..
………………

谢谢

我按照你说的输入了
但是一直有一排一排的命令出现
不知道是什么
gototop
 

【回复“baohe”的帖子】
【回复“我无邪”的帖子】
谢谢

日记如下

2006-09-10,20:09:51

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <pyjj><E:\拼音加加 V4.0B 正式版\jj4\jjsvr4.exe>  [加加开发组]
    <BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}><"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe">  [Nero AG]
    <Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTask><"C:\Program Files\rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"E:\Rising\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <NeroFilterCheck><C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe>  [Nero AG]
    <lingx><\linxe\Intrenet.exe>  []
    <自动安全清除临时文件><C:\WINDOWS\system32\Deltmp.bat>  []
    <Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <RavStub><"C:\Program Files\rising\Rav\ravstub.exe" /RUNONCE>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
服务
[Adobe LM Service / Adobe LM Service]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[JMediaService / JMediaService]
  <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service><N/A>
[NBService / NBService]
  <C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe><Nero AG>
[Network DDE / NetDDE]
  <C:\WINDOWS\system32\SVCH0ST.EXE><SMSoft>
[Rising Proxy  Service / RfwProxySrv]
  <e:\rising\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <e:\rising\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[User Profile Hive Cleanup / UPHClean]
  <C:\Program Files\UPHClean\uphclean.exe><N/A>
[Massacre / windows tmassacre]
  <><N/A>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[MetaProducts Inquiry Helper]
  {001165C1-A640-11D7-9FD9-0080481ADA61} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[Shockwave Flash Object]
  {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} <C:\WINDOWS\system32\smflash.ocx, Macromedia, Inc.>
[MyIEHelper Class]
  {16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5048.dll, N/A>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <E:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[google bar]
  {607E95A1-8F89-4343-B9BC-2EFC2B291BB4} <C:\WINDOWS\system32\googlebar.dll, Google Inc.>
[JMX.JmxCenter]
  {63859236-76BF-493C-A587-DF479EBA2D4B} <C:\WINDOWS\system32\EJMX.dll, 广州盛行网络有限公司>
[Vision]
  {6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\mmsass~1.dll, >
[YOK超级搜索]
  {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} <C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll, N/A>
[NTIECatcher Class]
  {C56CB6B0-0D96-11D6-8C65-B2868B609932} <C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll, Xi>
[MetaProducts &Inquiry]
  {49B46060-8AC4-11D7-9FD9-0080481ADA61} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[Save Flash files]
  {55AD98FF-3CB9-4718-B28B-E18F932D7FAB} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[MMSAssistMenu]
  {6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\mmsass~1.dll, >
[Save Page to Disk]
  {7FDB9AEE-D04A-440C-8D1D-52B807115C59} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[Save Images]
  {8F36E80B-AD7C-434E-AB92-DA3938EA01E5} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[保存网页内容]
  {B98EEB00-A0F2-11D7-9FD9-0080481ADA61} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[YOK超级搜索]
  {F869BB38-FFEF-4589-B986-610B7AD0ADA2} <C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll, N/A>
[网页快照工具栏(&I)]
  {B8238B20-FF2C-11D7-9FD9-0080481ADA61} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[MetaProducts Inquiry Helper]
  {001165C1-A640-11D7-9FD9-0080481ADA61} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[Shockwave Flash Object]
  {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} <C:\WINDOWS\system32\smflash.ocx, Macromedia, Inc.>
[MyIEHelper Class]
  {16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5048.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <E:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[google bar]
  {607E95A1-8F89-4343-B9BC-2EFC2B291BB4} <C:\WINDOWS\system32\googlebar.dll, Google Inc.>
[JMX.JmxCenter]
  {63859236-76BF-493C-A587-DF479EBA2D4B} <C:\WINDOWS\system32\EJMX.dll, 广州盛行网络有限公司>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Vision]
  {6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\mmsass~1.dll, >
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[YOK超级搜索]
  {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} <C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll, N/A>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <E:\迅雷\Components\InMedia\MediaAddin07.dll, Thunder Networking Technologies,LTD>
[网页快照工具栏(&I)]
  {B8238B20-FF2C-11D7-9FD9-0080481ADA61} <C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll, MetaProducts corp.>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[NTIECatcher Class]
  {C56CB6B0-0D96-11D6-8C65-B2868B609932} <C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll, Xi>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[YOK超级搜索]
  {F869BB38-FFEF-4589-B986-610B7AD0ADA2} <C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll, N/A>
[&使用迅雷下载]
  <E:\迅雷\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <E:\迅雷\Program\GetAllUrl.htm, N/A>
[>>彩信发送<<]
  <res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm, N/A>
[YOK超级搜索]
  <C:\Program Files\YOK.com\SuperSearch\yoksch.htm, N/A>
[上传到QQ网络硬盘]
  <E:\QQ\AddToNetDisk.htm, N/A>
[使用影音传送带下载]
  <C:\Program Files\Xi\NetTransport 2\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
  <C:\Program Files\Xi\NetTransport 2\NTAddList.html, N/A>
[保存完整框架(&F)                    ]
  <res://C:\Documents and Settings\new\桌面\网文快照\网页快照(绿色版)[1]\网页快照(绿色版)\inquiry.dll/saveframe.htm, N/A>
[保存完整网页(&P)                    ]
  <res://C:\Documents and Settings\new\桌面\网文快照\网页快照(绿色版)[1]\网页快照(绿色版)\inquiry.dll/savepage.htm, N/A>
[保存这张图片(&I)                    ]
  <res://C:\Documents and Settings\new\桌面\网文快照\网页快照(绿色版)[1]\网页快照(绿色版)\inquiry.dll/saveimg.htm, N/A>
[保存选择内容(&S)                        ]
  <res://C:\Documents and Settings\new\桌面\网文快照\网页快照(绿色版)[1]\网页快照(绿色版)\inquiry.dll/savesel.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <E:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\QQ\SendMMS.htm, N/A>

==================================
gototop
 

正在运行的进程
[PID: 288][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 348][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 372][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 416][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 428][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 576][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 632][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 672][C:\Program Files\rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 688][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 736][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 816][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 832][C:\Program Files\rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 35>
    [C:\Program Files\rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\rising\Rav\HOOKSYS.dll]  <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
    [C:\Program Files\rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 32>
    [C:\Program Files\rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 2>
    [C:\Program Files\rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 34>
    [C:\Program Files\rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [C:\Program Files\rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\rising\Rav\RSUnpack.dll]  <Beijing Rising Technology Co., Ltd.><1, 0, 0, 13>
    [C:\Program Files\rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\rising\Rav\ExtFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[PID: 1024][e:\rising\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [e:\rising\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [e:\rising\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [e:\rising\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [e:\rising\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [e:\rising\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1136][C:\Program Files\rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1300][e:\rising\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 52>
    [e:\rising\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [e:\rising\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [e:\rising\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1372][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [c:\windows\system32\tasklist.dll]  <N/A><N/A>
[PID: 1384][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1412][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\MMSASS~1\MMSSVER.DLL]  <><1, 2, 0, 5>
[PID: 1448][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1484][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1636][C:\Program Files\rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 1664][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3275>
[PID: 1672][C:\Program Files\rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
    [C:\Program Files\rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1728][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1736][E:\拼音加加 V4.0B 正式版\jj4\jjsvr4.exe]  <加加开发组><4.0.0.20>
[PID: 1744][C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe]  <Nero AG><1, 2, 0, 13>
    [C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll]  <Nero AG><3,15,2, 6900>
    [C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll]  <Nero AG><1, 2, 0, 13>
    [C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll]  <Nero AG><1, 2, 0, 13>
[PID: 1468][E:\迅雷\Program\Thunder5.exe]  <Thunder Networking Technologies,LTD><5.3.0.220>
    [E:\迅雷\Program\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
    [E:\迅雷\Program\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 4, 71>
    [E:\迅雷\Program\log4cplus.dll]  <><1, 0, 2, 1>
    [E:\迅雷\Program\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [E:\迅雷\Program\asyn_dns.dll]  <N/A><N/A>
    [E:\迅雷\Program\msgmanage.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 15>
    [E:\迅雷\Program\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 148>
    [E:\迅雷\Program\RegisterDll.dll]  <Thunder Networking Technologies,LTD><2, 1, 0, 18>
    [E:\迅雷\Program\FloatBar.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [E:\迅雷\Components\InMedia\iEmbedShell.dll]  < ><1, 0, 0, 11>
    [E:\迅雷\Components\InMedia\iEmbed04.dll]  < ><2, 3, 0, 37>
    [E:\迅雷\Components\P4PClient\P4PClient.dll]  <Thunder Networking Technologies,LTD><1, 0, 3, 8>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
gototop
 

[E:\迅雷\Program\iTargetAd.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 55>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\PROGRA~1\CNNIC\Cdn\iesrch.dll]  <CNNIC><2, 2, 0, 0>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 3148][E:\QQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [E:\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [E:\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [E:\QQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 160>
    [E:\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [E:\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [E:\QQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 3, 2, 1>
    [E:\QQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [E:\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [E:\QQ\QQMainFrame.dll]  <N/A><N/A>
    [E:\QQ\CQQApplication.dll]  <N/A><N/A>
    [E:\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [E:\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [E:\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [E:\QQ\MailSummary.dll]  <><1, 0, 0, 1>
    [E:\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [E:\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [E:\QQ\GroupLive.dll]  <N/A><N/A>
    [E:\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [E:\QQ\QQPlugin.dll]  <N/A><N/A>
    [E:\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [E:\QQ\QRingMng.dll]  <N/A><N/A>
    [E:\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [E:\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [E:\QQ\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [E:\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [E:\QQ\QQAllInOne.dll]  <N/A><N/A>
    [E:\QQ\SCCore.dll]  <N/A><N/A>
    [E:\QQ\QQCustomFace.dll]  <N/A><N/A>
    [E:\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [E:\QQ\QQAvatar.dll]  <N/A><N/A>
    [E:\QQ\QQSceneMng.dll]  <N/A><N/A>
    [E:\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
    [E:\QQ\BQQApplication.dll]  <N/A><N/A>
    [E:\QQ\GroupConnection.dll]  <Tencent><5, 0, 202, 170>
    [E:\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [E:\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [E:\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [E:\QQ\QQUdpGetFileLib.dll]  <tencent><0, 2, 2, 3>
    [E:\QQ\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 6, 60>
    [E:\QQ\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [E:\QQ\ShareFiles.dll]  <N/A><N/A>
[PID: 420][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3028][C:\WINDOWS\system32\Realplayer.exe]  <N/A><N/A>
[PID: 3920][E:\傲游\Maxthon\Max.exe]  <Maxthon International Ltd.><1, 5, 3, 18>
    [E:\傲游\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\Program Files\rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [E:\傲游\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\WINDOWS\system32\PYJJ4.IME]  <加加工作组><4.0.0.21>
[PID: 2336][E:\winamp\winamp.exe]  <Nullsoft><5,2,5,843>
    [E:\winamp\NSCRT.dll]  <Nullsoft, Inc.><7.10.0000>
    [E:\winamp\Plugins\gen_crasher.dll]  <Nullsoft><5,2,5,843>
    [E:\winamp\System\aacPlusDecoder.w5s]  <N/A><N/A>
    [E:\winamp\System\tagz.w5s]  <N/A><N/A>
    [E:\winamp\System\jnetlib.w5s]  <N/A><N/A>
    [E:\winamp\System\playlist.w5s]  <N/A><N/A>
    [E:\winamp\System\alac.w5s]  <N/A><N/A>
    [E:\winamp\System\filereader.w5s]  <N/A><N/A>
    [E:\winamp\System\xml.w5s]  <N/A><N/A>
    [E:\winamp\System\watcher.w5s]  <N/A><N/A>
    [E:\winamp\System\png.w5s]  <N/A><N/A>
    [E:\winamp\Plugins\in_mp3.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_wm.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_midi.dll]  <N/A><N/A>
    [E:\winamp\Plugins\read_file.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_mod.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_vorbis.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_mp4.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_cdda.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_wave.dll]  <N/A><N/A>
    [E:\winamp\libsndfile.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_ape.dll]  <Matthew T. Ashland><3.99>
    [E:\winamp\Plugins\in_mpc.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_flac.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_cue.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_nsv.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_dshow.dll]  <N/A><N/A>
    [E:\winamp\Plugins\in_linein.dll]  <N/A><N/A>
    [E:\winamp\Plugins\out_wave.dll]  <N/A><N/A>
    [E:\winamp\Plugins\out_disk.dll]  <Nullsoft><5,2,5,843>
    [E:\winamp\Plugins\out_ds.dll]  <N/A><N/A>
    [E:\winamp\Plugins\out_lame.dll]  <MUKOLI><1.6.3>
    [E:\winamp\Plugins\gen_ml.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_nowplaying.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_bookmarks.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_history.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_local.dll]  <N/A><N/A>
    [E:\winamp\nde.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_playlists.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_disc.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_rg.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_gusb_us.dll]  <N/A><N/A>
    [E:\winamp\Plugins\ml_transcode.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_ff.dll]  <N/A><N/A>
    [E:\winamp\Plugins\freeform\wacs\jpgload\jpgload.wac]  <N/A><N/A>
    [E:\winamp\Plugins\gen_lyricist.dll]  <http://www.lyricist.cn><1, 0, 3, 0>
    [E:\winamp\Plugins\gen_hotkeys.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_jumpex.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_tray.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_skinsubmenu.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_timerestore.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_find_on_disk.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_context.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_dragndrop.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_saveas.dll]  <N/A><N/A>
    [E:\winamp\Plugins\gen_cd_menu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 3336][C:\WINDOWS\explorer.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\Rsvtub.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
    [C:\DOCUME~1\new\桌面\网文快照\网页快~1\网页快~1\inquiry.dll]  <MetaProducts corp.><1.3.0.270>
    [C:\Program Files\Common Files\MetaProducts\mpapp.dll]  <MetaProducts corp.><1.4.0.260>
    [C:\WINDOWS\system32\smflash.ocx]  <Macromedia, Inc.><6.8.23.1>
    [C:\PROGRA~1\MMSASS~1\albus.dll]  <Albus><1, 0, 0, 2>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll]  <Nero AG><2, 2, 7, 0>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\PYJJ4.IME]  <加加工作组><4.0.0.21>
    [C:\WINDOWS\system32\EJMX.dll]  <广州盛行网络有限公司><1.03.0004>
    [C:\PROGRA~1\MMSASS~1\mmsass~1.dll]  <><1, 2, 0, 5>
    [C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll]  <Xi><1.91.12>
[PID: 1956][C:\Documents and Settings\new\桌面\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Documents and Settings\new\桌面\sreng2\SREng2\Plugins\SREngPluginDemo.SRE]  <Smallfrogs Studio><1, 1, 1, 0>

==================================
文件关联
.TXT  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [C:\WINDOWS\hh.exe %1]
.HLP  Error. [C:\WINDOWS\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

【回复“曾强”的帖子】
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []
木马。查杀参考:http://forum.ikaka.com/topic.asp?board=28&artid=8157088

——————
服务
[Network DDE / NetDDE]
<C:\WINDOWS\system32\SVCH0ST.EXE><SMSoft>
另外一个木马。删除这个服务项。重启。删除C:\WINDOWS\system32\SVCH0ST.EXE。注意不要删错文件。木马文件名中的『0』是数字。
——————


服务
[Massacre / windows tmassacre]
<><N/A>————这个服务项,不知道是什么。
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT