瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】真是要命SXS.exe的病毒啊,请高手解决

1   1  /  1  页   跳转

【求助】真是要命SXS.exe的病毒啊,请高手解决

【求助】真是要命SXS.exe的病毒啊,请高手解决

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <Internat.exe><internat.exe>  [(Verified)Microsoft Corporation]
    <svcshare><C:\WINNT\System32\drivers\spoclsv.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Corporation]
    <PRONoMgrWired><C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe>  [Intel(R) Corporation]
    <RaidTool><C:\Program Files\VIA\RAID\raid_tool.exe>  [VIA Technologies]
    <NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize>  [N/A]
    <nwiz><nwiz.exe /install>  [(Verified)NVIDIA Corporation]
    <CnsMin><Rundll32.exe C:\WINNT\DOWNLO~1\CnsMin.dll,Rundll32>  [北京三七二一科技有限公司]
    <xBarUpdate><C:\Program Files\xBar\xBarUpdate.exe>  [N/A]
    <TopDomainTDHelper><C:\WINNT\System32\TDHelp32.exe>  [N/A]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <图书馆管理系统服务器><d:\books\tlbk_svr\scktsrvr.exe>  [N/A]
    <Thunder><"D:\Program Files\Thunder Network\Thunder\Thunder.exe" /s>  [Thunder Networking Technologies,LTD]
    <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
    <2bqtsqw8vhs5><C:\WINNT\iexpiore.exe>  [N/A]
    <cu><C:\WINNT\winlog0n.exe>  [N/A]
    <Alitalk><C:\PROGRA~1\阿里巴巴\贸易通\AliTalk.EXE>  [Alibaba]
    <tmlurl><C:\WINNT\System32\ergaon.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <xBar><"C:\Program Files\xBar\update.exe">  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINNT\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINNT\DOWNLO~1\CnsHook.dll>  [北京三七二一科技有限公司]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINNT\System32\频道屏~1.SCR>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[服务管理器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\服务管理器.lnk --> C:\PROGRA~1\MICROS~3\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><N>

==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><N/A>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Dmsarrytps / Dmsarrytps][Stopped/Manual Start]
  <><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
  <d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
  <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[Intel NCS NetService / NetSvc][Stopped/Manual Start]
  <C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe><Intel(R) Corporation>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Auto Start]
  <C:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
[Siamrert / Siamrert][Stopped/Manual Start]
  <><N/A>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
  <d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\System32\mspmsnsv.dll><Microsoft Corporation>
最后编辑2007-01-13 14:26:04
分享到:
gototop
 

驱动程序
[1253781 / 1253781][Running/Boot Start]
  <\SystemRoot\System32\drivers\1253781.sys><N/A>
[a0 / a0][Running/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\1253781.sys><N/A>
[USB 2.0 (FS) ADFU Device / AdfuUd][Stopped/Manual Start]
  <System32\Drivers\AdfuUd.sys><>
[ADProt / ADProt][Running/System Start]
  <system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[aeaudio / aeaudio][Running/Manual Start]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CnsMinKP / CnsMinKP][Running/Boot Start]
  <\SystemRoot\System32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Intel(R) PRO/1000 Network Connection Driver / E1000][Running/Manual Start]
  <System32\DRIVERS\e1000nt5.sys><Intel Corporation>
[epffurg / epffurg][Running/Boot Start]
  <\SystemRoot\system32\drivers\epffurg.sys><>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[hardlock / hardlock][Running/Auto Start]
  <\??\C:\WINNT\System32\drivers\hardlock.sys><Aladdin Knowledge Systems>
[Haspnt / Haspnt][Running/Auto Start]
  <\??\C:\WINNT\System32\drivers\Haspnt.sys><Aladdin Knowledge Systems>
[HOOKAPI / HOOKAPI][Stopped/Manual Start]
  <\??\D:\PROGRAM FILES\RISING\RAV\HookApi.Sys><瑞星软件有限公司>
[HookCont / HookCont][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Stopped/Auto Start]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Feitian ROCKEY4 Device Service / ROCKEYNT][Running/Manual Start]
  <System32\DRIVERS\Rockey4.sys><Feitian Technologies Co., Ltd.>
[senfilt / senfilt][Running/Manual Start]
  <system32\drivers\senfilt.sys><Sensaura>
[smwdm / smwdm][Running/Manual Start]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>
[TDVideo / TDVideo][Running/System Start]
  <\??\C:\WINNT\System32\Drivers\TDVideo.sys><Nanjing Universal Networks (U-NET) Co., LTD.>
[VIA AGP Filter / viaagp1][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[viamraid / viamraid][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[VIA USB Host Controller Lower Filter / vulfnths][Running/Manual Start]
  <\SystemRoot\System32\Drivers\vulfnth.sys><VIA Technologies, Inc.>
[VIA USB Roothub Lower Filter / vulfntrs][Running/Manual Start]
  <\SystemRoot\System32\Drivers\vulfntr.sys><VIA Technologies, Inc.>

==================================
浏览器加载项
[Thunder Browser Helper]
  {0C7C23EE-A848-485B-873C-0ED954731014} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll, Thunder Networking Technologies,LTD>
[Tencent Browser Helper]
  {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[CMoveCatchPic Object]
  {0CF098A0-CBAC-4EFB-8451-3AFC201C7222} <C:\Program Files\xBar\xBarHelper.dll, N/A>
[Eye Class]
  {41BE3A3D-6E4B-43F4-AAEB-5B4E95971968} <C:\WINNT\System32\iodbzfex.dll, >
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
  {669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINNT\System32\ssup.dll, TENCENT>
[MAngle Class]
  {9A556B8F-FD02-420E-A1FD-9DB33808254E} <C:\Program Files\MySec\secmouseaai.dll, SemeanKitty's Office>
[BhoObj Class]
  {9C7BC48C-6EE7-43C4-A931-91F8DE3CD0D0} <C:\WINNT\System32\cuhqndbc.dll, >
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINNT\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <d:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[My 网蜜(&M)]
  {102293E4-758B-4483-946B-714EBCEC91B8} <C:\Program Files\MySec\secbaraai.dll, SemeanKitty's Office>
[Yahoo 3.5G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[名品折扣]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[雅虎WIDGET]
  {6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[My 网蜜(&M)]
  {102293E4-758B-4483-946B-714EBCEC91B8} <C:\Program Files\MySec\secbaraai.dll, SemeanKitty's Office>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\System32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[InfoCheck Class]
  {F91BA567-79B9-467E-BC97-5DBA01BBC5EE} <C:\PROGRA~1\阿里巴巴\贸易通\Ali_Check.dll, >
[InstallCheck Class]
  {FFB8C97E-39D4-4E8A-9FE4-B451A0D6CA65} <C:\PROGRA~1\阿里巴巴\贸易通\Ali_Check.dll, >
[!直接打开链接]
  <res://C:\Program Files\MySec\secmouseaai.dll/seopenurl.html, N/A>
[&使用迅雷下载]
  <D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
  <D:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[使用百度搜索]
  <res://C:\Program Files\MySec\secmouseaai.dll/sesch_bd.html, N/A>
[加入365MY收藏夹(&U)]
  <http://www.365my.com/rclick/add_url.php, N/A>
[加入365MY网摘(&N)]
  <http://www.365my.com/rclick/add_net.php, N/A>
[发送到手机]
  <C:\Program Files\xBar\xBar.htm, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
gototop
 

正在运行的进程
[PID: 148][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2170.1]
[PID: 180][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2137.1]
[PID: 176][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2182.1]
[PID: 228][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2191.1.296.2]
[PID: 240][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2184.1]
[PID: 408][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 436][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2161.1]
    [C:\WINNT\system32\CNMLM6e.DLL]  [CANON INC., 1.80.2.50]
    [C:\WINNT\system32\OLFMNT40.DLL]  [Microsoft Corporation, 9.0.98.0105]
    [C:\WINNT\System32\spool\PRTPROCS\W32X86\CNMPD6e.DLL]  [CANON INC., 1.80.2.50]
    [C:\WINNT\System32\spool\PRTPROCS\W32X86\olfpnt40.dll]  [Microsoft Corporation, 9.0.98.0105]
[PID: 480][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 508][d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe]  [Microsoft Corporation, 2000.080.0194.00]
[PID: 612][C:\WINNT\system32\regsvc.exe]  [Microsoft Corporation, 5.00.2155.1]
[PID: 704][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0001]
[PID: 960][C:\WINNT\Explorer.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
    [C:\WINNT\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [C:\WINNT\downlo~1\Kchtaa.dll]  [Tencent, 4, 4, 1, 14]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
    [C:\WINNT\System32\iodbzfex.dll]  [, 1, 0, 0, 4]
    [C:\WINNT\System32\cuhqndbc.dll]  [, 1, 0, 0, 24]
    [D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX]  [N/A, N/A]
    [D:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [d:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL]  [N/A, N/A]
    [C:\WINNT\System32\ergaon.dll]  [N/A, N/A]
[PID: 1064][C:\Program Files\VIA\RAID\raid_tool.exe]  [VIA Technologies, 4, 0, 6, 0]
    [C:\Program Files\VIA\RAID\drvInterface.dll]  [VIA, 4, 0, 4, 0]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
[PID: 1128][C:\WINNT\System32\TDHelp32.exe]  [N/A, N/A]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
[PID: 1140][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3427]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
[PID: 1180][C:\WINNT\System32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\ergaon.dll]  [N/A, N/A]
[PID: 536][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
    [C:\WINNT\System32\ergaon.dll]  [N/A, N/A]
[PID: 1320][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\downlo~1\Kchtaa.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
    [C:\Program Files\MySec\secbaraai.dll]  [SemeanKitty's Office, 1.00.05]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  [Tencent, 4, 4, 1, 14]
    [C:\Program Files\xBar\xBarHelper.dll]  [N/A, 1.0.0.8]
    [C:\WINNT\System32\iodbzfex.dll]  [, 1, 0, 0, 4]
    [d:\Program Files\Tencent\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [C:\WINNT\System32\ssup.dll]  [TENCENT, 4, 4, 1, 15]
    [C:\Program Files\MySec\secmouseaai.dll]  [SemeanKitty's Office, 1.00.04]
    [C:\WINNT\System32\cuhqndbc.dll]  [, 1, 0, 0, 24]
    [D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX]  [N/A, N/A]
    [C:\WINNT\System32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [C:\WINNT\System32\ergaon.dll]  [N/A, N/A]
[PID: 1352][C:\WINNT\System32\drivers\spoclsv.exe]  [N/A, N/A]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
[PID: 7196][C:\WINNT\System32\ergaon.exe]  [N/A, N/A]
    [C:\WINNT\System32\ergaon.dll]  [N/A, N/A]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
[PID: 9200][D:\瑞星专杀工具\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINNT\downlo~1\Jwgs.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINNT\System32\TDGL32.dll]  [N/A, N/A]
    [C:\WINNT\System32\ergaon.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[D:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[E:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[F:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

下面的方法解决不了
IceSword冰刃-斩断木马黑手的利刃
下载地址1:
中文:http://202.38.64.10/~jfpan/download/IceSword120_cn.zip
MD5 : cfb8514add1fbfb510b0084e837e561c

下载地址2:http://free.ys168.com/?ljs3508反病毒及安全工具区,
文件名:IceSword120_cn.zip 2.1MB

使用IceSword杀毒的一些基本操作
http://forum.ikaka.com/topic.asp?board=28&artid=7168178


展开:[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

<cmdbcs><C:\WINNT\cmdbcs.exe> [Microsoft Corporation]
<wabqpt><C:\WINNT\system32\ynxevc.exe> [N/A]

展开[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

<Userinit><C:\WINNT\system32\userinit.exe,C:\WINNT\system\userinit.exe> [N/A]红色的删掉

打开注册表编辑器,定位到HKEY_LOCAL_MACHINE\ SYSTEM\ CURRENT CONTROLSET\ SERVICES
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINNT\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
<C:\WINNT\system32\rundll32.exe xpdhcp.dll,start><Microsoft Corporation>
1、下载、运行IceSword。
2、用IceSword禁止进程创建。
3、找到并右击IceSword自身的进程名,点击“模块信息”。仔细查看模块中是否有
[C:\WINNT\system32\windhcp.ocx]
[C:\WINNT\system32\xpdhcp.dll]
[C:\WINNT\system32\ynxevc.dll] 。如果有,用IceSword强制卸除之(千万不要省略这一步)。
4、用IceSword结束除下列进程以外的进程(已经被病毒模块插入了):
[PID: 152][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 176][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 172][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6714]
[PID: 224][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.6700]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 236][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.6695]
[PID: 408][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 496][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.6659]
5、用IceSword删除上述加载项(红字内容)。
6、用IceSword删除以下文件。
C:\WINNT\system\userinit.exe
C:\WINNT\TEMP\gg.exe
C:\WINNT\system32\windhcp.ocx
C:\WINNT\system32\ynxevc.dll
C:\WINNT\system32\iexpl0re.exe
C:\WINNT\system32\windhcp.ocx
C:\WINNT\TEMP\LgSym.dll
C:\Progra~1\Eset\rund1132.exe
C:\WINNT\system32\windhcp.ocx
C:\WINNT\system32\xpdhcp.dll
C:\WINNT\system32\lexplore.exe
C:\WINNT\system\userinit.exe
删除D,E,F下的
Autorun.inf sxs.exe
清空。。C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

7、点击IceSword工具栏上的“文件”、“设置”,取消“禁止进程创建”。
8、点击IceSword工具栏上的“文件”、“重启并监视”。此时,系统重启。
禁用远程注册表修改服务。。重新扫日志传上来 给系统administrator 加密。。
gototop
 

求高手再指点
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT