瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求救!!!奇怪的SMSS病毒!!和一般的很不一样

12   2  /  2  页   跳转

求救!!!奇怪的SMSS病毒!!和一般的很不一样

回复:求救!!!奇怪的SMSS病毒!!和一般的很不一样

[&使用BitComet下载]
  <res://D:\下载软件\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
  <res://D:\下载软件\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
  <res://D:\下载软件\BitComet.exe/AddVideo.htm, N/A>
[使用迅雷下载]
  <D:\xunlei\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <D:\xunlei\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[查看当前站点排名]
  <http://alexa.chinaz.com/alexa.htm, N/A>
[添加到QQ表情]
  <D:\娱乐\QQ\AddEmotion.htm, N/A>
[转换为现有 PDF]
  <res://D:\阅读器7。0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换选定的链接为 Adobe PDF]
  <res://D:\阅读器7。0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
[转换选定的链接为现有 PDF]
  <res://D:\阅读器7。0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
[转换选项为 Adobe PDF]
  <res://D:\阅读器7。0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换选项为现有 PDF]
  <res://D:\阅读器7。0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换链接目标为 Adobe PDF]
  <res://D:\阅读器7。0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换链接目标为现有 PDF]
  <res://D:\阅读器7。0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>

==================================
正在运行的进程
[PID: 1160 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1232 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 1280 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1292 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 1476 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1568 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 1680 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\WINDOWS\System32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1740 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 1804 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 232 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp.050610-1527)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
[PID: 452 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\WINDOWS\system32\igfxpph.dll]  [Intel Corporation, 6.14.10.4820]
    [C:\WINDOWS\system32\hccutils.DLL]  [Intel Corporation, 6.14.10.4820]
    [C:\WINDOWS\system32\igfxres.dll]  [Intel Corporation, 6.14.10.4820]
    [C:\WINDOWS\system32\igfxress.dll]  [Intel Corporation, 6.14.10.4820]
    [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 6.14.10.4820]
    [D:\xunlei\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [D:\xunlei\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [D:\xunlei\Components\ResWorker\DsBho_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 19]
    [D:\xunlei\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [D:\rar\rarext.dll]  [N/A, ]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\ShellEx.dll]  [Kaspersky Lab, 7.0.0.125]
    [D:\Eplus\eppshell.dll]  [N/A, ]
[PID: 660 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\zhtfes.dll]  [N/A, ]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 872 / SYSTEM][d:\MICROS~1\MSSQL$SA\binn\sqlservr.exe]  [Microsoft Corporation, 2000.080.0194.00]
    [d:\MICROS~1\MSSQL$SA\binn\OPENDS60.DLL]  [Microsoft Corporation, 2000.080.0194.00]
    [d:\MICROS~1\MSSQL$SA\binn\UMS.DLL]  [Microsoft Corporation, 2000.080.0194.00]
    [d:\MICROS~1\MSSQL$SA\binn\SQLSORT.DLL]  [Microsoft Corporation, 2000.080.0194.00]
    [d:\MICROS~1\MSSQL$SA\binn\Resources\2052\sqlevn70.RLL]  [Microsoft Corporation, 2000.080.0194.00]
    [d:\MICROS~1\MSSQL$SA\binn\SSNETLIB.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [d:\MICROS~1\MSSQL$SA\binn\SSNMPN70.dll]  [Microsoft Corporation, 2000.080.0194.00]
    [d:\MICROS~1\MSSQL$SA\binn\SSmsLPCn.dll]  [Microsoft Corporation, 2000.080.0194.00]
[PID: 1492 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\yvfzvx.dll]  [N/A, ]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 1520 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1612 / SYSTEM][C:\WINDOWS\system32\EsEnt\services.exe]  [N/A, ]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1676 / SYSTEM][D:\Tomcat 5.5\bin\tomcat5.exe]  [Apache Software Foundation, 2.0.3.0]
    [D:\Java\jre1.5.0_09\bin\client\jvm.dll]  [Sun Microsystems, Inc., 5.0.90.3]
    [D:\Java\jre1.5.0_09\bin\hpi.dll]  [Sun Microsystems, Inc., 5.0.90.3]
    [D:\Java\jre1.5.0_09\bin\verify.dll]  [Sun Microsystems, Inc., 5.0.90.3]
    [D:\Java\jre1.5.0_09\bin\java.dll]  [Sun Microsystems, Inc., 5.0.90.3]
    [D:\Java\jre1.5.0_09\bin\zip.dll]  [Sun Microsystems, Inc., 5.0.90.3]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [D:\Java\jre1.5.0_09\bin\net.dll]  [Sun Microsystems, Inc., 5.0.90.3]
[PID: 2520 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 268 / SYSTEM][C:\WINDOWS\system32\Rules\smss.exe]  [N/A, ]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ntsvc.ocx]  [Microsoft, 1, 0, 0, 1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
[PID: 420 / SYSTEM][C:\WINDOWS\system32\Rules\services.exe]  [N/A, ]
    [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9782]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3136 / SYSTEM][C:\WINDOWS\system32\Rules\csrss.exe]  [N/A, ]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 4104 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Internet Explorer\MSIMG32.dll]  [FunWebProducts.com, 1, 0, 0, 5]
    [D:\xunlei\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [C:\WINDOWS\system32\TPHANDLE.dll]  [江苏科建教育软件有限责任公司, 5, 0, 10, 10]
    [D:\下载软件\tools\BitCometBHO_1.1.3.12.dll]  [BitComet, 20070312]
    [D:\Java\jre1.5.0_09\bin\ssv.dll]  [Sun Microsystems, Inc., 5.0.90.3]
    [D:\xunlei\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [D:\xunlei\Components\ResWorker\DsBho_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 19]
    [D:\xunlei\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\klscav.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prremote.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prloader.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prkernel.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\params.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\pxstub.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\tempfile.ppl]  [Kaspersky Lab, 7.0.0.125]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\nfio.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\fsdrvplg.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\basegui.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\thpimpl.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\FSSync.dll]  [Kaspersky Lab, 7.0.5.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\winreg.ppl]  [Kaspersky Lab, 7.0.0.125]
    [D:\xunlei\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 4, 23]
[PID: 68956 / Administrator][D:\xunlei\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.7.12.493]
    [D:\xunlei\Program\BugReport.dll]  [Thunder Networking Technologies,LTD, 1, 4, 1, 20]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\xunlei\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 3, 6, 66]
    [D:\xunlei\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 3, 1, 2, 311]
    [D:\xunlei\Program\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\xunlei\Program\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [D:\xunlei\Program\asyn_frame.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 13]
    [D:\xunlei\Program\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [D:\xunlei\Program\emule_id.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 7]
    [D:\xunlei\Program\backend_agent.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 17]
    [D:\xunlei\Program\ptl.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 18]
    [D:\xunlei\Program\xl_stat.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 3]
    [D:\xunlei\Program\fs.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 9]
    [D:\xunlei\Program\XLNet.Dll]  [Thunder Networking Technologies,LTD, 1, 5, 1, 24]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [D:\xunlei\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 10]
    [D:\xunlei\Components\DownAndPlay\DownAndPlay.dll]  [, 1, 0, 8, 26]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll]  [Kaspersky Lab, 7.0.0.125]
    [D:\xunlei\Program\p2sp.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 18]
    [D:\xunlei\Program\down_dispatcher.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 17]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\klscav.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prremote.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prloader.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\prkernel.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\params.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\pxstub.ppl]  [Kaspersky Lab, 7.0.0.125]
    [c:\program files\kaspersky lab\kaspersky anti-virus 7.0\tempfile.ppl]  [Kaspersky Lab, 7.0.0.125]
    [D:\xunlei\Program\p2p_upload.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 8]
    [D:\xunlei\Program\p2p.dll]  [Thunder Networking Technologies,LTD, 1,1,2,20]
    [D:\xunlei\Program\xldc.dll]  [Thunder Networking Technologies,LTD, 2, 6, 2, 12]
    [D:\xunlei\Program\stream.dll]  [Thunder Networking Technologies,LTD, 2, 1, 2, 359]
    [D:\xunlei\Program\iTargetAD.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 35]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
    [D:\xunlei\Program\p2p_local_res.dll]  [Thunder Networking Technologies,LTD, 1, 1, 2, 8]
    [D:\xunlei\Program\al.dll]  [Thunder Networking Technologies,LTD, 1,1,2,15]
    [D:\xunlei\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 2, 24]
gototop
 

回复:求救!!!奇怪的SMSS病毒!!和一般的很不一样

[D:\xunlei\Components\InMedia\iEmbed16.dll]  [Thunder Networking Technologies,LTD, 3, 4, 7, 103]
    [D:\xunlei\Components\InMedia\PlayerHelper.dll]  [thunder, 1, 1, 5, 41]
    [D:\xunlei\Components\InMedia\XLIPC.DLL]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [D:\xunlei\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 2, 2, 5, 70]
    [D:\xunlei\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 2, 1, 0, 38]
    [D:\xunlei\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 17, 0, 67]
    [D:\xunlei\Program\MSVCIRT.dll]  [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\xunlei\Components\Security\ThunderSafe.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 7, 79]
    [D:\xunlei\Components\Security\XLSafeUI.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 7, 79]
    [D:\xunlei\Components\Search\XLSearch.dll]  [Thunder Networking Technologies,LTD, 1, 1, 6, 21]
    [D:\xunlei\Program\LiveUpdate.dll]  [Thunder Networking Technologies,LTD, 1, 2, 3, 25]
    [D:\xunlei\Components\XLSoftBase\XLSoftwareBase.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 3]
    [D:\xunlei\Plugins\XLSafeHost\XLSafeHost.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 7, 59]
    [D:\xunlei\Components\ExplorerHelper\ExplorerHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 19]
    [D:\xunlei\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 4, 23]
    [D:\xunlei\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [D:\xunlei\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [D:\xunlei\Components\Tips\TipsClient.dll]  [Thunder Networking Technologies,LTD, 2, 2, 12, 108]
    [D:\xunlei\Components\VPSHELL\VPSHELL.dll]  [迅雷网络, 3, 0, 1, 33]
    [D:\xunlei\Components\UserExperience\UserExperience.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 4]
    [D:\xunlei\Components\ResWorker\DsXlCom.dll]  [, 1, 0, 0, 30]
    [D:\xunlei\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [D:\xunlei\Components\ResWorker\MediaWorker.dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 22]
    [D:\xunlei\Components\Tips\XLIPC.DLL]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [D:\xunlei\Components\DownloadStat\DownloadStat.dll]  [Thunder Networking Technologies,LTD, 1, 4, 1, 6]
    [D:\xunlei\Program\bd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 17]
[PID: 77928 / Administrator][D:\rar\WinRAR.exe]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 78884 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.188\SREngLdr.EXE]  [Smallfrogs Studio, 2.6.8.980]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
[PID: 79312 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.188\SRE4c3524b9.EXE]  [Smallfrogs Studio, 2.6.8.980]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]

==================================
文件关联
.TXT  Error. [UltraEdit.txt]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  Error. [UltraEdit.ini]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1  yu.8s7.net
127.0.0.1  2.joppnqq.com
127.0.0.1  1.joppnqq.com
127.0.0.1  1.jopenqc.com
127.0.0.1  xxx.vh7.biz
127.0.0.1  3.joppnqq.com
127.0.0.1  www.868wg.com
127.0.0.1  ilove.com
127.0.0.1  www.tomwg.com
127.0.0.1  www.22aaa.com
127.0.0.1  new.749571.com
127.0.0.1  cao.kv8.info
127.0.0.1  171817.171817.com
127.0.0.1  down.malasc.cn
127.0.0.1  nx.51ylb.cn
127.0.0.1  qqq.dzydhx.com
127.0.0.1  www.333292.com
127.0.0.1  up.22x44.com
127.0.0.1  bad.tqdlt.cn
127.0.0.1  c3.aishangai.net
127.0.0.1  xxx.188dm.com
127.0.0.1  d1.163500.net

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1676, D:\TOMCAT 5.5\BIN\TOMCAT5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 268, C:\WINDOWS\SYSTEM32\RULES\SMSS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3136, C:\WINDOWS\SYSTEM32\RULES\CSRSS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 68956, D:\XUNLEI\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 77928, D:\RAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 78884, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.188\SRENGLDR.EXE]

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

回复: 求救!!!奇怪的SMSS病毒!!和一般的很不一样

个人认为问题项目如下:

注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <helper.dll>
    <MyWebSearch Plugin>
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <system>

服务
[Application Management / AppMgmt]
[Task Card / Dutification]
[jakatf / jakatf]
[jzkqbh / jzkqbh]
[Remouters Access Auto / RpcServer]
[TCP/IP NetBIOS Help / LnHosts]

驱动程序
[LYFX / LYFX]
[SVKP / SVKP]

浏览器加载项
[&Search]
  <http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000, N/A>

可疑文件
C:\WINDOWS\system32\EsEnt\services.exe
C:\WINDOWS\system32\Rules\smss.exe
C:\WINDOWS\system32\Rules\services.exe
C:\WINDOWS\system32\Rules\csrss.exe
C:\WINDOWS\system32\drivers\LYFX.ahc(一个游戏的驱动,有人说其导致蓝屏)
c:\windows\system32\zhtfes.dll
C:\WINDOWS\System32\rclymv.dll
C:\WINDOWS\System32\xdgjdv.dll
c:\windows\system32\yvfzvx.dll
C:\WINDOWS\system32\SVKP.sys

建议将以下文件压缩,把压缩包提交“可疑文件交流区”鉴定
C:\WINDOWS\system32\EsEnt\services.exe
C:\WINDOWS\system32\Rules\smss.exe
C:\WINDOWS\system32\Rules\services.exe
C:\WINDOWS\system32\Rules\csrss.exe
C:\WINDOWS\system32\drivers\LYFX.ahc


注:可以通过以下方式尝试找到以下文件:
开始--运行--输入C:\WINDOWS\system32\EsEnt\--回车,找services.exe这个文件;
开始--运行--输入C:\WINDOWS\system32\rules\--回车,找services.exe、smss.exe、csrss.exe这三个文件。

感想:玩网络游戏的,基本上都在重复“游戏==中毒==杀毒=游戏”这样的恶性循环,郁闷……
最后编辑超级游戏迷 最后编辑于 2008-05-24 15:36:41
打酱油的……
gototop
 

回复:求救!!!奇怪的SMSS病毒!!和一般的很不一样

麻烦楼主将
C:\WINDOWS\system32\EsEnt\services.exe
C:\WINDOWS\system32\Rules\smss.exe
C:\WINDOWS\system32\Rules\services.exe
C:\WINDOWS\system32\Rules\csrss.exe
C:\WINDOWS\system32\drivers\LYFX.ahc

这几个文件打包发送agggg5566@hotmail.com

不甚感谢!
不认识我没关系,因为我也不认识你。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT