原帖由 天月来了 于 2009-11-22 9:47:00 发表
C:\WINDOWS\system32\IMM32.DLL文件,用解压工具WinRAR依路径打开,找到压缩发来看
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<autorun_19831028_kingsoftgo><"c:\windows\system32\jkjlonprq.exe" -at> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<mysys><C:\Program Files\Outlook_Express\SOUNDMAN.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
<{74DA2FEC-F68F-4DC7-9A45-9174AC044427}><C:\WINDOWS\system32\z6FVkEF47huPzgaXee.inf> []
<{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><C:\WINDOWS\system32\122B901E.dll> [File is missing]
<{B8D2813F-E0ED-42C6-95DD-2969BD5DC639}><C:\WINDOWS\fonts\AN2Epfv2VzeHreV.fon> []
<{9C788311-14C0-4A95-A2BD-560DAD76744E}><C:\WINDOWS\system32\EY5zY7JPqtgQ4mxgERCp5.inf> [File is missing]
<{827E2FB4-1047-43DE-848D-E12BB0C97AAB}><C:\WINDOWS\Tasks\SbrmpxjdCrgRAFhz4gHh.inf> [File is missing]
<{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}><C:\WINDOWS\fonts\A97CRaCB.fon> [File is missing]
<{61F8AFF1-7583-466C-A772-AAD4B4090514}><C:\Program Files\Internet Explorer\SDK.Dll> [File is missing]
<{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}><C:\WINDOWS\system32\ndxq9awMc.dll> [File is missing]
<{F181F067-7046-4DCB-993F-200990736305}><C:\WINDOWS\Downloaded Program Files\sZaeAC74EzXJeVeJu6p.cur> [File is missing]
<{B7F1BFDC-4B6C-4E2F-AF7A-638D2D47802C}><C:\WINDOWS\system32\FsmBY3kmWnAG5gRbwGgU.inf> []
<{87DE8A1A-96C5-4420-B222-EF998F697CE7}><C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.inf> []
<{7198F428-77AC-4837-AFBE-1E0393575935}><C:\WINDOWS\system32\JMq7bpeR4Xa8eV5ftCB.inf> [File is missing]
<{526EB425-7F56-4773-8D70-B8E45AA8E2B6}><C:\WINDOWS\Downloaded Program Files\WUstNjhyfQfpv8PQbC.cur> []
<{B9D0F4D7-C809-4C27-9CB4-63201DFB3D05}><C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf> [File is missing]
<{8A6A5B34-D995-4C5D-9338-B5E264B4A87}><C:\WINDOWS\system32\nXe2grrKNzF9dxYKmqg.inf> [File is missing]
<{73208305-2703-405b-8721-27645ac9a140}><C:\WINDOWS\system32\nWSDWJ9KSzcNsaTKtnSUwv8P7VU.inf> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
<IFEO[360tray.exe]><services.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
<IFEO[avp.exe]><services.exe> [(Verified)Microsoft Windows Component Publisher]
[LogeCenas Services Auto Logs / LogeCena][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k GaLoge-->C:\WINDOWS\system32\Logeukgcvzgg.dll><N/A>
[Vcs support / Vcs][Running/Auto Start]
<\??\C:\WINDOWS\system32\Drivers\Vcs.sys><N/A>
[xx / xx][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~1792740.ex><N/A>
[wohfgpqy / wohfgpqy][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\wohfgpqy.sys><N/A>
[hcpidesk / hcpidesk][Running/]
<2 - 系统找不到指定的文件。
><N/A>
这么多病毒加载项,你不管,仅仅让楼主发个DLL上来,管用?
——————————————————————————————————————————
[PID: 1472 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\kb021192919.dll] [N/A, ]
[C:\WINDOWS\system32\kb121192842.dll] [N/A, ]
[C:\WINDOWS\system32\kb221192853.dll] [N/A, ]
[C:\WINDOWS\system32\kb32119297.dll] [N/A, ]
[C:\WINDOWS\system32\kb521192933.dll] [N/A, ]
[C:\WINDOWS\system32\kb621192946.dll] [N/A, ]
[C:\WINDOWS\system32\kb821192959.dll] [N/A, ]
[C:\WINDOWS\system32\kb921193055.dll] [N/A, ]
[C:\WINDOWS\system32\kb1021193015.dll] [N/A, ]
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
[C:\WINDOWS\system32\z6FVkEF47huPzgaXee.inf] [N/A, ]
[C:\WINDOWS\fonts\AN2Epfv2VzeHreV.fon] [N/A, ]
[C:\WINDOWS\system32\FsmBY3kmWnAG5gRbwGgU.inf] [N/A, ]
[C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.inf] [N/A, ]
[C:\WINDOWS\Downloaded Program Files\WUstNjhyfQfpv8PQbC.cur] [N/A, ]
[C:\WINDOWS\system32\nWSDWJ9KSzcNsaTKtnSUwv8P7VU.inf] [N/A, ]
[C:\WINDOWS\system32\syslib .dll] [N/A, ]
\winlogon.exe进程以及大多应用程序进程都插入了这些病毒模块。不清理被插进程?咋搞?
——————————————————————————
[PID: 136 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\31763.exe] [N/A, ]
[C:\WINDOWS\system32\kb02285031.dll] [N/A, ]
[C:\WINDOWS\Downloaded Program Files\WUstNjhyfQfpv8PQbC.cur] [N/A, ]
[C:\WINDOWS\system32\kb12284956.dll] [N/A, ]
[C:\WINDOWS\system32\FsmBY3kmWnAG5gRbwGgU.inf] [N/A, ]
[C:\WINDOWS\system32\nWSDWJ9KSzcNsaTKtnSUwv8P7VU.inf] [N/A, ]
[C:\WINDOWS\system32\kb2228508.dll] [N/A, ]
[C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.inf] [N/A, ]
[C:\WINDOWS\system32\kb32285019.dll] [N/A, ]
[C:\WINDOWS\system32\kb52285044.dll] [N/A, ]
[C:\WINDOWS\system32\kb62285057.dll] [N/A, ]
[C:\WINDOWS\system32\kb8228518.dll] [N/A, ]
[C:\WINDOWS\system32\kb92285157.dll] [N/A, ]
[C:\WINDOWS\system32\kb102285120.dll] [N/A, ]
病毒进程不想法结束,咋搞?
——————————————————————————————
特殊特权被允许: SeLoadDriverPrivilege [PID = 4360, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SYSLOG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 4952, C:\PROGRAM FILES\OUTLOOK_EXPRESS\SOUNDMAN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3760, C:\DOCUMENTS AND SETTINGS\WINDOWS\MSE\MSE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 136, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\31763.EXE]
这些已经取得系统特权的病毒进程,不想法灭掉?