瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我又中网络木马了。。高手急救下有了扫描日记了

1   1  /  1  页   跳转

我又中网络木马了。。高手急救下有了扫描日记了

我又中网络木马了。。高手急救下有了扫描日记了

2006-12-25,16:25:21

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(IMJPMIG8.1)("C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [(Verified)Microsoft Corporation]
(PHIME2002ASync)(C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [(Verified)Microsoft Corporation]
(PHIME2002A)(C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [(Verified)Microsoft Corporation]
(RfwMain)(C:\Program Files\Rising\Rfw\rfwmain.exe) [Beijing Rising Technology Corporation Limited]
(nod32kui)("C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE) [(Verified)Eset ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [(Verified)Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(Cmaudio)(; RunDll32 cmicnfg.cpl,CMICtrlWnd) [N/A]
(Micro)(; C:\WINDOWS\Microsoft\rundll32.exe) [N/A]
(miniqqlive)(; "C:\Program Files\Tencent\QQLive\MiniQQLive.exe") [Tencent]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(MSMSGS)(; "C:\Program Files\Messenger\msmsgs.exe" /background) [(Verified)Microsoft Corporation]
(MsnMsgr)(; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background) [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(StormCodec_Helper)(; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti) [N/A]




--------------------------------------------------------------------------------



启动文件夹

N/A



--------------------------------------------------------------------------------



服务

[NOD32 Kernel Service / NOD32krn]
("C:\Program Files\Eset\nod32krn.exe")(Eset)
[Rising Personal Firewall Service / RfwService]
(c:\program files\rising\rfw\rfwsrv.exe)(Beijing Rising Technology Corporation Limited)
最后编辑2006-12-25 16:32:41
分享到:
gototop
 

驱动程序

[a347bus / a347bus]
(\SystemRoot\system32\DRIVERS\a347bus.sys)()
[a347scsi / a347scsi]
(\SystemRoot\System32\Drivers\a347scsi.sys)()
[AMON / AMON]
(\SystemRoot\system32\drivers\amon.sys)(Eset)
[标准 IDE/ESDI 硬盘控制器 / atapi]
(\SystemRoot\system32\DRIVERS\atapi.sys)(N/A)
[ati2mtag / ati2mtag]
(system32\DRIVERS\ati2mtag.sys)(ATI Technologies Inc.)
[BaseTDI / BaseTDI]
(\??\C:\WINDOWS\system32\drivers\basetdi.sys)(Rising)
[C-Media WDM Audio Interface / cmuda]
(system32\drivers\cmuda.sys)(C-Media Inc)
[FwDrv / FwDrv]
(\??\c:\program files\rising\rfw\FwDrv.sys)(Rising)
[nod32drv / nod32drv]
(\SystemRoot\system32\drivers\nod32drv.sys)(N/A)
[npkcrypt / npkcrypt]
(\??\C:\Program Files\Tencent\QQ\npkcrypt.sys)(INCA Internet Co., Ltd.)
[npkcusb / npkcusb]
(\??\C:\Program Files\Tencent\QQ\npkcusb.sys)(INCA Internet Co., Ltd.)
[Direct Parallel Link Driver / Ptilink]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
(system32\DRIVERS\RTL8139.SYS)(Realtek Semiconductor Corporation)
[Secdrv / Secdrv]
(system32\DRIVERS\secdrv.sys)(N/A)



--------------------------------------------------------------------------------



浏览器加载项

[Flashget Catch Url Class]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} (C:\PROGRA~1\FLASHGET\jccatch.dll, www.flashget.com)
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} (C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll, Thunder Networking Technologies,LTD)
[gFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} (C:\Program Files\FlashGet\getflash.dll, )
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} (C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD)
[快车]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} (C:\PROGRA~1\FLASHGET\flashget.exe, FlashGet.com)
[快车(FlashGet)]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} (C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} (%SystemRoot%\system32\mshtml.dll, N/A)
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} (C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation)
[Flashget Catch Url Class]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} (C:\PROGRA~1\FLASHGET\jccatch.dll, www.flashget.com)
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} (%SystemRoot%\system32\shdocvw.dll, N/A)
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} (C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation)
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} (C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll, Thunder Networking Technologies,LTD)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\system32\shdocvw.dll, N/A)
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} (C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation)
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[快车(FlashGet)]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} (C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft)
[gFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} (C:\Program Files\FlashGet\getflash.dll, )
[&使用快车(FlashGet)下载]
(C:\PROGRA~1\FLASHGET\jc_link.htm, N/A)
[&使用快车(FlashGet)下载全部链接]
(C:\PROGRA~1\FLASHGET\jc_all.htm, N/A)
[&使用迅雷下载]
(C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A)
[&使用迅雷下载全部链接]
(C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A)
[上传到QQ网络硬盘]
(C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A)
[添加到QQ自定义面板]
(C:\Program Files\Tencent\QQ\AddPanel.htm, N/A)
[添加到QQ表情]
(C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A)
[用QQ彩信发送该图片]
(C:\Program Files\Tencent\QQ\SendMMS.htm, N/A)



--------------------------------------------------------------------------------
gototop
 

正在运行的进程

[PID: 448][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 572][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 584][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[PID: 732][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 776][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[PID: 852][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[PID: 892][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[PID: 956][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[PID: 1200][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1396][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\FLASHGET\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\PROGRA~1\FLASHGET\jccatch.dll] [www.flashget.com, 1, 8, 0, 1002]
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\Eset\nodshex.dll] [N/A, N/A]
[PID: 1508][C:\Program Files\Rising\Rfw\rfwmain.exe] [Beijing Rising Technology Corporation Limited, 3, 0, 0, 79]
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 17, 0, 0, 30]
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 17, 0, 0, 15]
[C:\Program Files\Rising\Rfw\PngDll.dll] [Rising, 17, 0, 0, 2]
[C:\PROGRA~1\FLASHGET\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[PID: 1516][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\nod32rui.dll] [N/A, N/A]
[C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_amon.dll] [N/A, N/A]
[C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_dmon.dll] [N/A, N/A]
[C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_emon.dll] [N/A, N/A]
[C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_nod32.dll] [N/A, N/A]
[C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_upd.dll] [N/A, N/A]
[C:\PROGRA~1\FLASHGET\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[PID: 1524][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1984][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\nod32krr.dll] [N/A, N/A]
[C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_amon.dll] [N/A, N/A]
[C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_dmon.dll] [N/A, N/A]
[C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_emon.dll] [N/A, N/A]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_nod32.dll] [N/A, N/A]
[C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_upd.dll] [N/A, N/A]
[PID: 2008][c:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Corporation Limited, 3, 0, 0, 79]
[c:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Corporation Limited, 3, 0, 0, 35]
[c:\program files\rising\rfw\rfwrule.dll] [Beijing Rising Technology Corporation Limited, 3, 0, 0, 79]
[c:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Technology Corporation Limited, 3, 0, 0, 79]
[PID: 1700][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\FLASHGET\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\PROGRA~1\FLASHGET\jccatch.dll] [www.flashget.com, 1, 8, 0, 1002]
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[C:\Program Files\FlashGet\getflash.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 1376][C:\BT\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\PROGRA~1\FLASHGET\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 16 ]
[C:\Program Files\Eset\pr_imon.dll] [Eset , 2, 70, 16 ]



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------



Winsock 提供者

NOD32 protected [MSAFD Tcpip [TCP/IP]]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [UDP/IP]]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [RAW/IP]]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP UDP Service Provider]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP TCP Service Provider]
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32
C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)



--------------------------------------------------------------------------------



Autorun.inf

N/A



--------------------------------------------------------------------------------



HOSTS 文件

127.0.0.1 localhost
gototop
 

删除这一项后删除相应文件
(Micro)(; C:\WINDOWS\Microsoft\rundll32.exe) [N/A]
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT