1   1  /  1  页   跳转

进程里有N个ctfmon.exe

进程里有N个ctfmon.exe

进程里有N个ctfmon.exe 有时多到几十个! 用瑞星最新版在安全模式里什么也杀不出来,
不进入安全模式开不出,双击没反映!
最后编辑2007-05-30 16:33:19
分享到:
gototop
 

引用:
【231243234242的贴子】进程里有N个ctfmon.exe 有时多到几十个! 用瑞星最新版在安全模式里什么也杀不出来,
不进入安全模式开不出,双击没反映!
………………

ctfmon.exe
名称: alternative user input services
描述: ctfmon.exe是microsoft office产品套装的一部分。它可以选择用户文字输入程序,和微软office xp语言条。这不是纯粹的系统程序,但是如果终止它,可能会导致不可知的问题
gototop
 

请问是什么原因导致出现这个问题的?
gototop
 

去下载sreng2,关闭qq,下载软件等一切不必要的程序后扫个日志上来,一次贴不完分段贴,不要修改
http://www.kztechs.com/sreng/sreng2.zip
gototop
 

扫描结果!
[CODE]

2007-05-30,15:20:47

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <360Safetray><E:\杀毒\360safe\safemon\360Tray.exe /start>  [奇虎网]
    <runeip><E:\杀毒\卡卡\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <SiSPower><Rundll32.exe SiSPower.dll,ModeAgent>  [Silicon Integrated Systems Corporation]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RavScanBD><"c:\program files\rising\rfw\ScanBD.exe" /INST>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <RavStub><"C:\PROGRAM FILES\RISING\RAV\ravstub.exe" /RUNONCE>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><E:\征途外挂\逍遥游1[3211].1.rar\antiScanner.dll>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]

==================================
启动文件夹
N/A
gototop
 

==================================
服务
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard][Stopped/Auto Start]
  <E:\杀毒\ewido\ewido anti-spyware 4.0\guard.exe><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[EQSysSecure / EQSysSecure][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\EQSysSecure.sys><EQSecure>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver][Stopped/System Start]
  <\??\E:\杀毒\ewido\ewido anti-spyware 4.0\guard.sys><N/A>
[ExpScaner / ExpScaner][Others/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
[HookCont / HookCont][Others/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
[HookReg / HookReg][Others/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
[HookSys / HookSys][Others/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[MEMSCAN / MEMSCAN][Others/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\QQ\QQ程序\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Others/Auto Start]
  <\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SiS315 / SiS315][Running/Manual Start]
  <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
[SiSkp / SiSkp][Running/System Start]
  <system32\DRIVERS\srvkp.sys><Silicon Integrated Systems Corporation>
[ATSpy / ATSpy][Running/Manual Start]
  <\??\C:\WINDOWS\system32\ATSpy.sys><N/A>

==================================
浏览器加载项
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\杀毒\360safe\safemon\safemon.dll, >
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <E:\迅雷WED\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[WebThunder Class]
  {03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\杀毒\360safe\safemon\safemon.dll, >
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[上传到QQ网络硬盘]
  <D:\QQ\QQ程序\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
  <E:\迅雷WED\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
  <E:\迅雷WED\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
  <D:\QQ\QQ程序\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\QQ\QQ程序\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\QQ\QQ程序\SendMMS.htm, N/A>

==================================
gototop
 

正在运行的进程
N/A

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1 LOCALHOST
219.238.233.202 www.ztztzt.com.cn
219.238.233.202 www.blackzl.com
219.238.233.202 www.555125.com
58.218.179.154 www.youxig.com
58.218.179.154 bbs.youxig.com
58.218.179.154 www.ztztzt.com
58.218.179.154 bbs.ztztzt.com
58.218.179.154 ztztzt.com
219.238.233.202 www.loveuc.com
219.238.233.202 www.wowchian.com
219.238.233.202 wowchian.com
219.238.233.202 www.zhengtusf.com
219.238.233.202 zhengtusf.com
219.238.233.202 zhengtu.uuh.cn
219.238.233.202 www.ztgmme.com.cn
219.238.233.202 ztgmme.com.cn
219.238.233.202 www.zt.yn9.cn
219.238.233.202 www.221122.net
219.238.233.202 www.171737.com
219.238.233.202 www.yxcb.com
219.238.233.202 www.zt930.com
219.238.233.202 zt930.com
219.238.233.202 yxcb.com
219.238.233.202 171737.com
219.238.233.202 www.sy5832.com
219.238.233.202 221122.net
219.238.233.202 18dmm.com
219.238.233.202 www.18dmm.com
219.238.233.202 sa.cn
219.238.233.202 1.sa.cn
219.238.233.202 www.2007ip.com
219.238.233.202 2007ip.com
219.238.233.202 56jb.com
219.238.233.202 iloveck.com
219.238.233.202 www.iloveck.com
219.238.233.202 www.5yip.com
219.238.233.202 mmm.caifu18.net
219.238.233.202 d.qbbd.com
219.238.233.202 www.5117music.com
219.238.233.202 www.union123.com
219.238.233.202 www.wu7x.cn
219.238.233.202 www.54699.com
219.238.233.202 60.169.0.66
219.238.233.202 60.169.1.29
219.238.233.202 www.97725.com
219.238.233.202 down.97725.com
219.238.233.202 ip.315hack.com
219.238.233.202 www.baidulink.com
219.238.233.202 do.77276.com
219.238.233.202 www.down.hunll.com
219.238.233.202 www.hunll.com
219.238.233.202 www.9cyy.com
219.238.233.202 www.heixiou.com
219.238.233.202 xulao.com
219.238.233.202 www.41ip.com
219.238.233.202 www1.cw988.cn
219.238.233.202 d.77276.com
219.238.233.202 i.96981.com
219.238.233.202 www.my6688.cn
219.238.233.202 wm.103715.com
219.238.233.202 www.guazhan.cn
219.238.233.202 www.f5game.com
219.238.233.202 222.73.220.45
219.238.233.202 www1.cw988.cn
219.238.233.202 adnx.yygou.cn
219.238.233.202 cool.47555.com
219.238.233.202 www.asdwc.com
219.238.233.202 55880.cn
219.238.233.202 www.5i73.com
219.238.233.202 mir2.5i73.com

==================================
API HOOK
N/A

==================================
隐藏进程
    [112] C:\WINDOWS\system32\ctfmon.exe
    [428] \SystemRoot\System32\smss.exe
    [500] \??\C:\WINDOWS\system32\csrss.exe
    [524] \??\C:\WINDOWS\system32\winlogon.exe
    [568] C:\WINDOWS\system32\services.exe
    [580] C:\WINDOWS\system32\lsass.exe
    [740] C:\WINDOWS\system32\svchost.exe
    [852] C:\Program Files\Rising\Rav\CCenter.exe
    [1072] C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
    [1264] C:\WINDOWS\Explorer.EXE
    [1288] c:\program files\rising\rfw\rfwsrv.exe
    [1428] C:\WINDOWS\system32\spoolsv.exe
    [1508] C:\WINDOWS\System32\alg.exe
    [1572] C:\PROGRAM FILES\RISING\RAV\RavStub.exe
    [1760] E:\杀毒\360safe\safemon\360Tray.exe
    [1768] E:\杀毒\卡卡\runiep.exe
    [1776] C:\WINDOWS\SOUNDMAN.EXE
    [1848] C:\Program Files\Rising\Rav\RavTask.exe
    [1864] C:\Program Files\Rising\Rav\Ravmon.exe
    [1936] C:\Program Files\Internet Explorer\iexplore.exe
    [2028] C:\Program Files\Rising\Rfw\rfwmain.exe
    [2060] C:\WINDOWS\system32\taskmgr.exe
    [2468] C:\WINDOWS\system32\wuauclt.exe
    [2520] C:\Documents and Settings\123456789\桌面\3333333333333333333333333333\SREng.EXE
    [2924] C:\Program Files\Rising\Rav\RsAgent.exe
    [2944] C:\WINDOWS\msagent\AgentSvr.exe

==================================


[/CODE]
gototop
 

电脑开的时间越久,ctfmon.exe进程久越多!

附件附件:

下载次数:1044
文件类型:application/octet-stream
文件大小:
上传时间:2007-5-30 15:49:36
描述:



gototop
 

外挂等同于后门.
gototop
 

用外挂的结果......
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT