瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 怎么就根除不了我中的毒,并附日志请教大虾

12   1  /  2  页   跳转

怎么就根除不了我中的毒,并附日志请教大虾

怎么就根除不了我中的毒,并附日志请教大虾

1。开机就有这个对话框跳出来

附件附件:

下载次数:452
文件类型:application/octet-stream
文件大小:
上传时间:2006-7-24 17:01:56
描述:



最后编辑2006-07-24 17:23:08
分享到:
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=6979213 下载四楼的工具。运行后进入“系统修复”--“启动项”删除你上面图里说的那一项。
gototop
 

开机总是显示加载c:\ progra~1\baidu\iexp\BDSrHook.DLL失败
2。然后今天的瑞星扫描结果如下图:
瑞星扫描显示
文件名 exploere.exe  路径c:\windows\explorer.exe  中了Backdoor.agent.ddb
文件名 aceci.exe 路径c:\!submit 中了trojan.DL.agent
如下图

附件附件:

下载次数:435
文件类型:application/octet-stream
文件大小:
上传时间:2006-7-24 17:07:52
描述:



gototop
 

然后用木马杀客扫描,但是上周五和今天的扫描结果不同,先看今天的
结果显示c:\windows\system32\netsend.exe 中了backdoor.Gpigeon.3239
但是实际上这个c:\windows\system32\netsend.exe 我已经用KILLBOX删除过了的,所以我觉得很奇怪
且上周五的木马杀客扫描结果又没有显示这个,只显示c:\windows\_msrstrt.exe中了木马重启程序.475

附件附件:

下载次数:408
文件类型:application/octet-stream
文件大小:
上传时间:2006-7-24 17:12:12
描述:



gototop
 

然后我扫描日志,见下。之所以啰里啰唆说这么多,就是想请教大虾,看看能不能完全的清除干净,之前我也作了不少尝试,总是不干净。。。。
2006-07-24,16:47:05

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [Microsoft Corporation]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <BIE><RUNDLL32.EXE C:\PROGRA~1\baidu\iexp\BDSrHook.dll,Rundll32>  []
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <Acrobat Assistant 7.0><; "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe">  [Adobe Systems Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><EXPLORER.EXE>  [Microsoft Corporation]
    <Userinit><userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\aceci.exe,C:\WINDOWS\system32\netsend.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><C:\Program Files\TGTSoft\StyleXP\CurrentLogon.EXE>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <stdup><>  []

==================================
启动文件夹
服务
[Adobe LM Service / Adobe LM Service]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
  <C:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[PDEngine / PDEngine]
  <"C:\Program Files\Raxco\PerfectDisk\PDEngine.exe"><Raxco Software, Inc.>
[PDScheduler / PDSched]
  <"C:\Program Files\Raxco\PerfectDisk\PDSched.exe"><Raxco Software, Inc.>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Serv-U FTP 服务器 / Serv-U]
  <C:\Program Files\Serv-U\ServUDaemon.exe><Cat Soft>
[StdService / StdService]
  <C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\STDSVER.DLL,Service><N/A>
[StyleXPService / StyleXPService]
  <"C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"><>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[FltSetUp Class]
  {1D49D58D-5C84-4B50-8359-D9809BEB2B32} <C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll, Microsoft Corporation>
[CpapView Class]
  {77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\Rundll32.dll, N/A>
[IEHlprObj Class]
  {999ADFA2-8AD1-47ff-97FC-69FB847458F4} <C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484f-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[IEHlprObj Class]
  {BA623AA0-9A82-4d0c-944C-0228CEA17780} <C:\Progra~1\Messenger\msgsf.dll, Microsoft Corporation>
[IEHlprObj Class]
  {F5B3ECED-9BF3-4f7e-882B-A6E75343C499} <C:\Progra~1\NetMeeting\netinit.dll, N/A>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[FltSetUp Class]
  {1D49D58D-5C84-4B50-8359-D9809BEB2B32} <C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll, Microsoft Corporation>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[CpapView Class]
  {77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\Rundll32.dll, N/A>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[IEHlprObj Class]
  {999ADFA2-8AD1-47FF-97FC-69FB847458F4} <C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484F-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[IEHlprObj Class]
  {BA623AA0-9A82-4D0C-944C-0228CEA17780} <C:\Progra~1\Messenger\msgsf.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[IEHlprObj Class]
  {F5B3ECED-9BF3-4F7E-882B-A6E75343C499} <C:\Progra~1\NetMeeting\netinit.dll, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[转换为 Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换为现有 PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换选定的链接为 Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
[转换选定的链接为现有 PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
[转换选项为 Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换选项为现有 PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换链接目标为 Adobe PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换链接目标为现有 PDF]
  <res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
gototop
 

运行:regedit,按F3搜索"c:\ progra~1\baidu\iexp\BDSrHook.DLL"找到后删除,或者运行:msconfig--启动--找到相应的把前面的钩去掉.
gototop
 

正在运行的进程
[PID: 1252][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1388][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1460][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1568][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1596][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1836][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1964][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 244][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 276][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 296][C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe]  <><0, 20, 0, 3000>
[PID: 512][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 456][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 684][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 29>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 964][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1060][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs]  <Adobe Systems Inc.><7.0.0.2004121400\0>
    [C:\WINDOWS\system32\xunleibho_v8.dll]  <><4, 5, 1, 33>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1380][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\system32\AdobePDF.dll]  <Adobe Systems Incorporated.><7.0.0.00>
    [C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS]  <N/A><N/A>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL]  <Zenographics, Inc.><5.60.709.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDM32.DLL]  <Zenographics, Inc.><5, 60, 1511, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZGDI32.dll]  <Zenographics, Inc.><5, 60, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZTAG32.dll]  <Zenographics, Inc.><5, 60, 1210, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDMUI.DLL]  <Zenographics, Inc.><5, 60, 1520, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SR32.dll]  <Zenographics, Inc.><5, 60, 1407, 0>
[PID: 1660][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 668][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 796][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  <Microsoft Corporation><7.00.9466>
[PID: 828][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 180][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=8105899
下载HijackThis...把日志帖上来..
  用这个也扫一份上来。那日志看得头晕。。。。
gototop
 

[C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 1048][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 328][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.0.34>
[PID: 388][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 336][C:\Program Files\Serv-U\ServUDaemon.exe]  <Cat Soft><6.1.0.1>
    [C:\Program Files\Serv-U\libeay32.DLL]  <N/A><N/A>
    [C:\Program Files\Serv-U\ssleay32.DLL]  <N/A><N/A>
[PID: 696][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1068][C:\Program Files\Raxco\PerfectDisk\PDSched.exe]  <Raxco Software, Inc.><7, 0, 0, 34>
    [C:\Program Files\Raxco\PerfectDisk\PDCommon.dll]  <Raxco Software, Inc.><7, 0, 0, 34>
    [C:\Program Files\Raxco\PerfectDisk\PDLangEN.dll]  <Raxco Software, 公司.><7, 0, 0, 34>
    [C:\Program Files\Raxco\PerfectDisk\PDSchedPS.dll]  <Raxco Software, Inc.><7, 0, 0, 34>
    [C:\Program Files\Raxco\PerfectDisk\PDEnginePS.dll]  <Raxco Software, Inc.><7, 0, 0, 34>
[PID: 2864][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3668][C:\Program Files\lotus\notes\NLNOTES.EXE]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nnotesws.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nnotes.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nxmlpar.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nxmlcommon.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\js32.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\NLSCCSTR.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\ndgts.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\LTOUIN22.dll]  <Lotus Development Corporation.><2.2.0.8911>
    [C:\Program Files\lotus\notes\nplugins.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\NSTRINGS.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\namhook.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nTCP.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nNWSPX.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nNETBIOS.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nstclientu.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nimuiu.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nimuires.dll]  <><3, 1, 0, 1>
    [C:\Program Files\lotus\notes\nNTCP.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nlsxbe.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\ninfobox.dll]  <Lotus Development Corporation><1.0.0.0>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\IMFNT5.DLL]  <Zenographics, Inc.><0, 3, 1418, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZTAG32.dll]  <Zenographics, Inc.><5, 60, 1210, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Imf32.dll]  <Zenographics, Inc.><5, 60, 1204, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL]  <Zenographics, Inc.><5.60.709.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDM32.DLL]  <Zenographics, Inc.><5, 60, 1511, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZGDI32.dll]  <Zenographics, Inc.><5, 60, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDMUI.DLL]  <Zenographics, Inc.><5, 60, 1520, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SR32.dll]  <Zenographics, Inc.><5, 60, 1407, 0>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\lotus\notes\nDBnotes.DLL]  <N/A><N/A>
[PID: 776][C:\Program Files\lotus\notes\ntaskldr.EXE]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nnotes.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nxmlpar.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nxmlcommon.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\js32.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\NLSCCSTR.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\ndgts.dll]  <N/A><N/A>
    [C:\Program Files\lotus\notes\NSTRINGS.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nhkdaemn.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nhldaemn.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\namhook.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nTCP.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nNWSPX.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nNETBIOS.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nwebdll.DLL]  <N/A><N/A>
    [C:\Program Files\lotus\notes\nNTCP.DLL]  <N/A><N/A>
[PID: 3176][C:\Program Files\Rising\Rav\rav.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 75>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RsStore.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[PID: 2444][C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe]  <Adobe Systems Inc.><6.0.1.2004121400>
    [C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.chs]  <Adobe Systems Inc.><6.0.0.0>
gototop
 

[PID: 3656][E:\software\杀毒软件\病毒清除\木马杀客\mmsk.exe]  <木马杀客><2,0,0,6>
    [E:\software\杀毒软件\病毒清除\木马杀客\krnln.fnr]  <><1, 0, 0, 1>
    [E:\software\杀毒软件\病毒清除\木马杀客\HtmlView.fne]  <><1, 0, 0, 1>
    [E:\software\杀毒软件\病毒清除\木马杀客\iext.fnr]  <><1, 0, 0, 1>
    [E:\software\杀毒软件\病毒清除\木马杀客\TrayIcon.fne]  <><1, 0, 0, 1>
    [E:\software\杀毒软件\病毒清除\木马杀客\iext2.fne]  <><1, 0, 0, 1>
    [E:\software\杀毒软件\病毒清除\木马杀客\iext3.fne]  <><1, 0, 0, 1>
    [E:\software\杀毒软件\病毒清除\木马杀客\xplib.fne]  <N/A><N/A>
    [E:\software\杀毒软件\病毒清除\木马杀客\shell.fne]  <N/A><N/A>
    [E:\software\杀毒软件\病毒清除\木马杀客\dp1.fne]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [E:\software\杀毒软件\病毒清除\木马杀客\eAPI.fne]  <><1, 0, 0, 1>
[PID: 2232][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\xunleibho_v8.dll]  <><4, 5, 1, 33>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll]  <Adobe Systems Incorporated><7.0.0.0>
    [C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.CHS]  <Adobe Systems Incorporated><7.0.0.0>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\Internet Explorer\Plugins\Brio8\axbqs32.dll]  <Hyperion Solutions Corporation><8.3.2.122>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL]  <Zenographics, Inc.><5.60.709.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDM32.DLL]  <Zenographics, Inc.><5, 60, 1511, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZGDI32.dll]  <Zenographics, Inc.><5, 60, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZTAG32.dll]  <Zenographics, Inc.><5, 60, 1210, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDMUI.DLL]  <Zenographics, Inc.><5, 60, 1520, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SR32.dll]  <Zenographics, Inc.><5, 60, 1407, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\IMFNT5.DLL]  <Zenographics, Inc.><0, 3, 1418, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Imf32.dll]  <Zenographics, Inc.><5, 60, 1204, 0>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 3844][C:\Program Files\MSN Messenger\msnmsgr.exe]  <Microsoft Corporation><7.5.0324>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1072][E:\software\杀毒软件\扫描日志的\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT