瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 机子变得好慢,请高手们帮我看一下日志.

1234   4  /  4  页   跳转

机子变得好慢,请高手们帮我看一下日志.

[C:\WINDOWS\system32\wsock32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RASAPI32.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rasman.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\sensapi.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_gdr.070614-1242)]
    [C:\WINDOWS\system32\mswsock.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\hnetcfg.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\wship6.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\CLBCATQ.DLL]  [Microsoft Corporation, 2001.12.4414.308]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
    [C:\WINDOWS\system32\LINKINFO.dll]  [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]
    [C:\WINDOWS\system32\ntshrui.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ATL.DLL]  [Microsoft Corporation, 3.05.2284]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
RSVP UDP Service Provider
    C:\WINDOWS\VMailDog.dll(北信源, Vmaildog)
RSVP TCP Service Provider
    C:\WINDOWS\VMailDog.dll(北信源, Vmaildog)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
61.152.108.76  www.work009.com
61.152.108.76  my.m365m.com
61.152.108.76  www.mh578.com

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1504, C:\PROGRA~1\MCAFEE.COM\AGENT\MCTSKSHD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1844, C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1892, C:\PROGRA~1\MCAFEE.COM\AGENT\MCAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 244, C:\PROGRA~1\MCAFEE.COM\VSO\MCVSESCN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1108, D:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2680, D:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3792, D:\PROGRAM FILES\3721\SKE\TROJANASSISTANT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3792, D:\PROGRAM FILES\3721\SKE\TROJANASSISTANT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2492, D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A
gototop
 

楼主安装了McAfee。用它扫一下QQ的安装目录(楼主的电脑上是D:\Program Files\Tencent\QQ),如果有病毒就清除。

其实我个人觉得对这类拷贝到QQ目录的木马,还是用卡巴斯基的比较好一些。至于瑞星卡卡,楼主不妨也试试。
gototop
 
1234   4  /  4  页   跳转
页面顶部
Powered by Discuz!NT