瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 帮我看看这个文件是否有病毒或者木马

12   2  /  2  页   跳转

[已解决] 帮我看看这个文件是否有病毒或者木马

回复:帮我看看这个文件是否有病毒或者木马

[CODE]



[PID: 3232 / lsd][C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe]  [Motorola Inc., 6.12.05]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Motorola\SMSERIAL\sm56eng.dll]  [Motorola Inc., 6.12.05]
    [C:\Program Files\Motorola\SMSERIAL\sm56fra.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56brz.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56chs.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56cht.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56ger.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56ita.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56jpn.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56esp.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56kor.dll]  [, ]
    [C:\Program Files\Motorola\SMSERIAL\sm56dnk.dll]  [, ]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
[PID: 3488 / lsd][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 11.1.21 03Jul08]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\SynCOM.dll]  [Synaptics, Inc., 11.1.21 03Jul08]
    [C:\WINDOWS\system32\SynTPAPI.dll]  [Synaptics, Inc., 11.1.21 03Jul08]
[PID: 3652 / lsd][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL]  [Lenovo Group Limited, 1, 0, 0, 0]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\SC\PWRMGRRT.DLL]  [N/A, ]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL]  [N/A, ]
    [C:\WINDOWS\system32\Sensor.dll]  [Lenovo., 1.60.0.6]
    [C:\WINDOWS\system32\OEMDSPIF.DLL]  [ATI Technologies, Inc., 6.14.0016]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\ATM.DLL]  [Lenovo Japan, 1, 3, 4, 0]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
[PID: 3668 / lsd][C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe]  [Lenovo Group Limited, 1.04]
    [C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.dll]  [Lenovo Group Limited, 1.00]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll]  [Lenovo Group Limited, 1.01]
[PID: 3832 / lsd][C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\Program Files\Alwil Software\Avast4\English\Base.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\Program Files\Alwil Software\Avast4\English\Lang.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [c:\program files\alwil software\avast4\ahruijs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\ashUInt.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\PROGRA~1\ALWILS~1\Avast4\XT1922.dll]  [Codejock Software, 1, 9, 4, 0]
    [c:\program files\alwil software\avast4\ahruimai.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [c:\program files\alwil software\avast4\ahruimes.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [c:\program files\alwil software\avast4\ahruins.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [c:\program files\alwil software\avast4\ahruiout.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [c:\program files\alwil software\avast4\ahruip2p.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [c:\program files\alwil software\avast4\ahruistd.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [c:\program files\alwil software\avast4\ahruiws.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
[PID: 3932 / lsd][C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe]  [Lenovo Group Limited, 5.01]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
[PID: 4024 / lsd][C:\Program Files\Lenovo\Zoom\TpScrex.exe]  [Lenovo Group Limited, 2.03]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
[PID: 220 / lsd][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 11.1.21 03Jul08]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\SynCOM.dll]  [Synaptics, Inc., 11.1.21 03Jul08]
[PID: 1536 / lsd][C:\Program Files\DAEMON Tools Lite\daemon.exe]  [DT Soft Ltd, 4.30.3]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\MFC80CHS.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\Program Files\DAEMON Tools Lite\Engine.dll]  [DTSoft Ltd, 4.30.3]
    [C:\Program Files\DAEMON Tools Lite\daemon.dll]  [DT Soft Ltd., 4.30.0.0]
    [C:\Program Files\DAEMON Tools Lite\imgengine.dll]  [DT Soft Ltd., 1.17.0.0]
[PID: 2096 / lsd][C:\WINDOWS\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
[PID: 2644 / lsd][C:\WINDOWS\system32\conime.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
[PID: 4004 / lsd][C:\Program Files\Mozilla Firefox\firefox.exe]  [Mozilla Corporation, 1.9.0.5]
    [C:\Program Files\Mozilla Firefox\xul.dll]  [Mozilla Foundation, 1.9.0.5]
    [C:\Program Files\Mozilla Firefox\sqlite3.dll]  [sqlite.org, 3.5.9]
    [C:\Program Files\Mozilla Firefox\MOZCRT19.dll]  [Mozilla Foundation, 8.00.0000]
    [C:\Program Files\Mozilla Firefox\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\Program Files\Mozilla Firefox\nspr4.dll]  [Mozilla Foundation, 4.7.1]
    [C:\Program Files\Mozilla Firefox\smime3.dll]  [Mozilla Foundation, 3.12.2.0 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nss3.dll]  [Mozilla Foundation, 3.12.2.0 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssutil3.dll]  [Mozilla Foundation, 3.12.2.0 Basic ECC]
    [C:\Program Files\Mozilla Firefox\plc4.dll]  [Mozilla Foundation, 4.7.1]
    [C:\Program Files\Mozilla Firefox\plds4.dll]  [Mozilla Foundation, 4.7.1]
    [C:\Program Files\Mozilla Firefox\ssl3.dll]  [Mozilla Foundation, 3.12.2.0 Basic ECC]
    [C:\Program Files\Mozilla Firefox\xpcom.dll]  [Mozilla Foundation, 1.9.0.5]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll]  [Mozilla Foundation, 1.9.0.5]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 70, 0, 1]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [ , 2, 60, 0, 1]
    [C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll]  [Mozilla Foundation, 1.9.0.5]
    [C:\Program Files\Mozilla Firefox\softokn3.dll]  [Mozilla Foundation, 3.12.2.0 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssdbm3.dll]  [Mozilla Foundation, 3.12.2.0 Basic ECC]
    [C:\Program Files\Mozilla Firefox\freebl3.dll]  [Mozilla Foundation, 3.12.2.0 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssckbi.dll]  [Mozilla Foundation, 1.72]
    [C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll]  [Lenovo Group Limited, 1.01]
    [C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll]  [, ]
    [C:\WINDOWS\system32\icm32.dll]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 4.0.0.1959]
[PID: 3680 / lsd][C:\Program Files\SogouInput\4.0.0.1959\PinyinUp.exe]  [Sogou.com Inc., 4.0.0.1959]
    [C:\Program Files\SogouInput\4.0.0.1959\HWSignature.dll]  [Sogou.com Inc., 4.0.0.1959]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [ , 2, 60, 0, 1]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 70, 0, 1]
[PID: 3312 / lsd][C:\tools\SREng\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
[PID: 3320 / lsd][C:\tools\SREng\SRE25160059.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1007]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 8, 1296, 0]
    [C:\tools\SREng\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [ , 2, 60, 0, 1]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 70, 0, 1]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
PROXIFIER MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\PrxerDrv.dll(Initex Software, ProxifierDrv)
VMCI sockets DGRAM
    C:\Program Files\VMware\VMware Workstation\vsocklib.dll(VMware, Inc., VSockets Library)
VMCI sockets STREAM
    C:\Program Files\VMware\VMware Workstation\vsocklib.dll(VMware, Inc., VSockets Library)
PROXIFIER LSP
    C:\WINDOWS\system32\PrxerDrv.dll(Initex Software, ProxifierDrv)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 3232, C:\PROGRAM FILES\MOTOROLA\SMSERIAL\SM56HLPR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2096, C:\WINDOWS\SYSTEM32\INTERNAT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3312, C:\TOOLS\SRENG\SRENGLDR.EXE]

==================================
计划任务
[已启用] SogouImeMgr.job
        C:\PROGRA~1\SOGOUI~1\400~1.195\PinyinRepair.exe
[已禁用] PMTask.job
        C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================
gototop
 

回复: 帮我看看这个文件是否有病毒或者木马

哥,请以附件形式上传。
gototop
 

回复:帮我看看这个文件是否有病毒或者木马

好的,请在1楼下载看看,有劳各位了
gototop
 

回复:帮我看看这个文件是否有病毒或者木马

我觉得没啥问题
gototop
 

回复:帮我看看这个文件是否有病毒或者木马

那看来问题就是那个我已经删掉的服务serggggy了。
gototop
 

回复:帮我看看这个文件是否有病毒或者木马

LZ可以上传internat.exe这个文件上来么?
我要确定下,碰到好几个了
gototop
 

回复:帮我看看这个文件是否有病毒或者木马

internat.exe上传. 搜索一下..把路径也报上来..
这个有点怀疑..别的没什么
最后编辑whzl999 最后编辑于 2009-02-02 11:18:04
gototop
 

回复:帮我看看这个文件是否有病毒或者木马

internat.exe 在system32下

此文件请到1楼下载,谢谢。
gototop
 

回复:帮我看看这个文件是否有病毒或者木马

那文件没问题
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT