使用nimaya杀毒的结果如下:
文件名 路径 处理结果
Winlog \??\C:\WINDOWS\system32\csrss.exe 拒绝访问
smss.exe \SystemRoot\System32\smss.exe 拒绝访问
csrss.exe \??\C:\WINDOWS\system32\csrss.exe 拒绝访问
autoru C: D: E: F: autorun.inf 成功删除
上述三个拒绝访问的文件是否为应该删除的病毒?
详细进程扫描如下:
==================================
正在运行的进程
[PID: 560][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 624][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 648][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 860][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1020][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1064][C:\ WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1192][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1360][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\lxcglmpm.DLL] [, 1.154.7.0]
[C:\WINDOWS\system32\LXPRMON.DLL] [N/A, N/A]
[C:\WINDOWS\system32\IMGMAN32.dll] [Data Techniques, Inc., 7.20 ]
[C:\WINDOWS\system32\IM31IMG.DIL] [Data Techniques, Inc., 7.20 ]
[C:\WINDOWS\system32\LXPMONRC.DLL] [Lexmark International, Inc., 1.0.6.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\lxcgPP5C.dll] [Lexmark International, Inc., 2.15.111.14]
[PID: 1488][C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00]
[PID: 1560][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1968][C:\WINDOWS\system32\devgt.exe] [Microsoft Corporation, 5.01.2600]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 1984][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[C:\DOCUME~1\EADING\LOCALS~1\Temp\ZtgQ.dll] [N/A, N/A]
[C:\WINDOWS\EagleFlt.dll] [N/A, N/A]
[C:\Program Files\Acrobatchs\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[PID: 428][C:\Program Files\Lenovo\网络爸爸\EagleSvr.exe] [tuEagles, 6.5.4.14]
[C:\Program Files\Lenovo\网络爸爸\eaglep.dll] [N/A, N/A]
[C:\Program Files\Lenovo\网络爸爸\EglLogin.dll] [N/A, N/A]
[C:\Program Files\Lenovo\网络爸爸\eagler.dll] [N/A, N/A]
[C:\Program Files\Lenovo\网络爸爸\eaglek.dll] [N/A, N/A]
[C:\Program Files\Lenovo\网络爸爸\eaglet.dll] [N/A, N/A]
[C:\Program Files\Lenovo\网络爸爸\EagleC.dll] [N/A, N/A]
[C:\Program Files\Lenovo\网络爸爸\workdll.dll] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 540][F:\Program Files\KaKa\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[F:\Program Files\KaKa\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[PID: 548][C:\WINDOWS\system32\ewnjqa.exe] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 620][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 628][C:\WINDOWS\system32\drivers\spoclsv.exe] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 760][C:\DOCUME~1\EADING\LOCALS~1\Temp\Zt2\SVCH0ST.EXE] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\DOCUME~1\EADING\LOCALS~1\Temp\ZtgQ.dll] [N/A, N/A]
[PID: 1000][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] [Microsoft Corporation, 2000.080.0194.00]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 1088][F:\苏备迎\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[F:\苏备迎\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 160]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\苏备迎\QQ\LoginCtrl.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 3, 2, 1]
[F:\苏备迎\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[F:\苏备迎\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[F:\苏备迎\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[F:\苏备迎\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[F:\苏备迎\QQ\QQMainFrame.dll] [N/A, N/A]
[F:\苏备迎\QQ\CQQApplication.dll] [N/A, N/A]
[F:\苏备迎\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[C:\DOCUME~1\EADING\LOCALS~1\Temp\ZtgQ.dll] [N/A, N/A]
[F:\苏备迎\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\QQPlugin.dll] [N/A, N/A]
[F:\苏备迎\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[F:\苏备迎\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[F:\苏备迎\QQ\QQAvatar.dll] [N/A, N/A]
[F:\苏备迎\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[PID: 3772][F:\苏备迎\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[F:\苏备迎\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3552][F:\下载\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\ewnjqa.dll] [N/A, N/A]
[F:\Program Files\KaKa\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[C:\DOCUME~1\EADING\LOCALS~1\Temp\ZtgQ.dll] [N/A, N/A]
==================================
大侠,敬请指教——