本人受木马的困惑已经几个月了,一直无法彻底清除,电脑上同时开启了,天网防火墙,木马清道夫2006,木马清道夫防火墙,木马杀客,恶劣软件清楚,瑞星正版.......依然无法把木马正法,高手帮小弟看看到底该怎么解决,万分感谢~~!!!!
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<SoundMan><SOUNDMAN.EXE> [Avance Logic, Inc.]
<SKYNET Personal FireWall><D:\PROGRA~1\SKYNET\FIREWALL\pfw.exe> [广州众达天网技术有限公司]
<StormCodec_Helper><"D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<Knight V><> []
<Windows木马防火墙><D:\Program Files\ftc\Trojanwall.exe> [风云谷]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<alsmt.exe><D:\WINDOWS\system32\alsmt.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><D:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
服务
[JMediaService / JMediaService]
<D:\WINDOWS\system32\rundll32.exe D:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service><N/A>
==================================
浏览器加载项
[Vision]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <D:\PROGRA~1\MMSASS~1\mmsass~1.dll, >
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <D:\PROGRA~1\MMSASS~1\mmsass~1.dll, >
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[易趣购物]
{DE607141-AC19-421e-867A-7D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <D:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Vision]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <D:\PROGRA~1\MMSASS~1\mmsass~1.dll, >
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\system32\Macromed\Flash\Flash.ocx, Macromedia, Inc.>
[>>彩信发送<<]
<res://D:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 444][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 504][\??\D:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 528][\??\D:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 572][D:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 584][D:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 728][D:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 776][D:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 844][D:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 900][D:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 952][D:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 1252][D:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[D:\PROGRA~1\MMSASS~1\mmsass~1.dll] <><1, 2, 0, 6>
[PID: 1284][D:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 1544][D:\WINDOWS\SOUNDMAN.EXE] <Avance Logic, Inc.><5.0.07>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 1584][D:\Program Files\ftc\Trojanwall.exe] <风云谷><5.4.0.1912>
[D:\Program Files\ftc\ftcapi.dll] <fygsoft><1.1.0.0>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 1596][D:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 1760][D:\WINDOWS\system32\rundll32.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\PROGRA~1\MMSASS~1\MMSSVER.DLL] <><1, 2, 0, 6>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 760][D:\WINDOWS\system32\wscntfy.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 964][D:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 1808][D:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 2256][D:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[PID: 2372][D:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[D:\PROGRA~1\MMSASS~1\mmsass~1.dll] <><1, 2, 0, 6>
[D:\WINDOWS\system32\Macromed\Flash\Flash.ocx] <Macromedia, Inc.><6,0,84,0>
[PID: 2940][D:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
[D:\PROGRA~1\MMSASS~1\mmsass~1.dll] <><1, 2, 0, 6>
[D:\WINDOWS\system32\Macromed\Flash\Flash.ocx] <Macromedia, Inc.><6,0,84,0>
[PID: 3312][D:\Documents and Settings\zhujing\桌面\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[D:\Program Files\ftc\SocketMon.dll] <Fygsoft and Microsoft><1.1.1.0>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["D:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]