瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 csrss,ctfnom.exe,cmd.exe这些东西,怎么弄阿

12   1  /  2  页   跳转

csrss,ctfnom.exe,cmd.exe这些东西,怎么弄阿

csrss,ctfnom.exe,cmd.exe这些东西,怎么弄阿

各位大哥,小弟我前天下载了个视频剪切软件,解压后是个.exe得可执行文件,可是后来双击后,却是个唐伯虎点秋香的电子书小说,虽然名字写着什么剪切软件,但是却是这个东西,我怀疑是病毒,所以马上删除该电子书,可是还是来不及了,一堆一堆的东西通过木马清道夫提示在系统文件夹中建立的文件,而且有东西写入了注册表,立马我的电脑就处于半瘫,我于是打开瑞星进行查杀,有几个蠕虫被干掉,还有几个木马,各位也都了解,瑞星对于木马的作用不大,所以我有用木马清道夫查杀,结果还真有几个,我怕有漏网之鱼,用木马杀客用弄了一遍,这会还真没有查出
但是到了我第二次用电脑的时候,瑞星开机扫描就扫描出了几个病毒,又是蠕虫(不过之后再也没有查出来),我以为这些病毒已经销声匿迹,但是我却发现,我的双核电脑却连魔兽争霸玩着都卡的不行,我察看了任务管理器,结果有发现csrss.exe一直占用cpu,最高的时候有26%,我以为这是正常的程序,可是我看了我的同样配置得笔记本电脑,这个电脑里面的csrss却占用了只有0%~1%,另外,在每次启动windows的时候都会在系统文件夹上建立一个ctfnom.exe的文件,用木马清道夫杀毒,这个病毒随即被干掉,可是不幸得事,在任务管理器中我还发现了cmd.exe得东西,占用cpu为50%,天啊,卡拉,我后来从网上看到,ctfnom.exe,csrss,cmd.exe都是病毒借用系统文件的名字,产生的病毒,可是,无论是用WoptiClean清除那个twin流氓软件,还是安全模式下杀毒,都不能杀毒,让我极为难过,祈求各位高手,告诉我怎么弄这个东西,谢谢
最后编辑2007-03-12 23:46:08
分享到:
gototop
 

2007-03-11,21:03:04

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [N/A]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Windows Publisher]
    <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)Microsoft Windows Publisher]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Publisher]
    <nwiz><nwiz.exe /install>  []
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <Windows木马防火墙><D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\Trojanwall.exe>  [风云谷]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <WebThunder><D:\Program Files\迅雷\WebThunder.exe>  [深圳市迅雷网络技术有限公司]
    <SunJavaUpdateSched><C:\Program Files\Java\jre1.6.0\bin\jusched.exe>  [Sun Microsystems, Inc.]
    <mppds><C:\WINDOWS\mppds.exe>  []
    <upxdnd><C:\DOCUME~1\hedy\LOCALS~1\Temp\upxdnd.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>  [Beijing Rising Technology Co., Ltd.]
    <zwotdp66><%systemroot%\system32\Rundll32.exe %systemroot%\system32\zwotdp66.dll,DllUnregisterServer>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <twin><C:\WINDOWS\system32\ctfnom.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)]
    <Userinit><C:\WINDOWS\system32\userinit.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\夜光时~1.SCR>  []
gototop
 

启动文件夹
[服务管理器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\服务管理器.lnk --> C:\PROGRA~1\MICROS~4\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><N>
[木马杀客2007]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\木马杀客2007.Lnk --> C:\PROGRA~1\木马杀客\mmsk.exe [N/A]><N>
[珊瑚虫]
  <C:\Documents and Settings\hedy\「开始」菜单\程序\启动\珊瑚虫.lnk --> C:\PROGRA~1\Tencent\QQ\CoralQQ.exe [珊瑚虫工作室]><N>
[Stardock ObjectDock]
  <C:\Documents and Settings\hedy\「开始」菜单\程序\启动\Stardock ObjectDock.lnk --> C:\WINDOWS\BRICOP~1\VISTAI~1\OBJECT~1\OBJECT~1.EXE [Stardock]><N>
[Y'z ToolBar]
  <C:\Documents and Settings\hedy\「开始」菜单\程序\启动\Y'z ToolBar.lnk --> C:\WINDOWS\BRICOP~1\VISTAI~1\YZTOOL~1\YZTOOL~1.EXE [Y'z@Home]><N>

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
  <C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
  <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
  <C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Windows CreaterDown / WindowsDown][Stopped/Auto Start]
  <C:\WINDOWS\system32\Webrvet.exe><N/A>

==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[dhmmjq7 / dhmmjq74][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\dhmmjq74.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[pabhmn8 / pabhmn85][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\pabhmn85.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver / RTL8023][Running/Manual Start]
  <system32\DRIVERS\Rtlnic51.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SiSide / SiSide][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\siside.sys><Silicon Integrated Systems Corp.>
[sisidex / sisidex][Running/Boot Start]
  <\SystemRoot\system32\drivers\sisidex.sys><Windows (R) 2000 DDK provider>
[Add Performance Filter Driver / sisperf][Running/Boot Start]
  <\SystemRoot\system32\drivers\sisperf.sys><Silicon Integrated Systems Corp.>
[SiSRaid2 / SiSRaid2][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\SiSRaid2.sys><Silicon Integrated Systems Corp>
[zwotdp6 / zwotdp66][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\zwotdp66.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
gototop
 

浏览器加载项
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\Program Files\迅雷\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0\bin\ssv.dll, Sun Microsystems, Inc.>
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[易趣购物]
  {DE60714F-AC17-427e-861A-FD60CBDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=1, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Java Plug-in]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in]
  {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\Program Files\迅雷\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[YOKHttpFilter Class]
  {686D3343-D00D-49A1-96DF-66F3AF62F348} <C:\Program Files\yok\adblock.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[YOKAdBlock Class]
  {718F4AD3-70D4-425E-9159-5598DFC732ED} <C:\Program Files\yok\adblock.dll, N/A>
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0\bin\ssv.dll, Sun Microsystems, Inc.>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <D:\Program Files\迅雷\MediaAddin10.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
  <D:\Program Files\聊天\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
  <D:\Program Files\迅雷\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
  <D:\Program Files\迅雷\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\聊天\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\聊天\AddEmotion.htm, N/A>
[珊瑚虫超级搜索]
  <C:\Program Files\yok\yoksch.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\聊天\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
  <E:\BitSpirit\bsurl.htm, N/A>
gototop
 

正在运行的进程
[PID: 464][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 532][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 556][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\system32\winlib .dll]  [N/A, ]
[PID: 600][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 612][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 768][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
[PID: 824][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 892][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 908][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 976][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 1048][C:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\psapi.dll]  [Microsoft Corporation, 4.00]
    [C:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [C:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [C:\Program Files\Rising\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\SpamEng.dll]  [, 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 26]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 41]
    [C:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RsVM.dll]  [, 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
    [C:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[PID: 1636][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\system32\mppds.dll]  [N/A, ]
    [C:\DOCUME~1\hedy\LOCALS~1\Temp\upxdnd.dll]  [N/A, ]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\Vista\Rtback\ContextBG.dll]  [Grigri, 1, 0, 0, 1]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [D:\soft\杀毒工具\安装程序\WINDOW~1\WINDOW~1\ftcsetup\Commenu.dll]  [Fygsoft and Microsoft, 3.0.0.63]
gototop
 

[PID: 1664][c:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
    [c:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [c:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [c:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [c:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [c:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
[PID: 1872][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3208]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1940][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.34]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1964][D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\Trojanwall.exe]  [风云谷, 4.7.0.1405]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\ftcapi.dll]  [fygsoft, 1.0.0.0]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PSAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1972][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
[PID: 1988][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
    [C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
[PID: 2000][C:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
[PID: 184][C:\Program Files\Java\jre1.6.0\bin\jusched.exe]  [Sun Microsystems, Inc., 6.0.0.66]
    [C:\Program Files\Java\jre1.6.0\bin\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
[PID: 948][C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe]  [Y'z@Home, 1, 3, 0, 0]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\Languages\English.lang]  [ , 1, 0, 0, 0]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2936][D:\Program Files\聊天\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\Program Files\聊天\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [D:\Program Files\聊天\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [D:\Program Files\聊天\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\Program Files\聊天\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\Program Files\聊天\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [D:\Program Files\聊天\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [D:\Program Files\聊天\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [D:\Program Files\聊天\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\Program Files\聊天\QQMainFrame.dll]  [N/A, ]
    [D:\Program Files\聊天\CQQApplication.dll]  [N/A, ]
    [D:\Program Files\聊天\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\QQSpace.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [D:\Program Files\聊天\QQAllInOne.dll]  [N/A, ]
    [D:\Program Files\聊天\GroupLive.dll]  [N/A, ]
    [D:\Program Files\聊天\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [D:\Program Files\聊天\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\QQSysMsgMng.dll]  [N/A, ]
    [D:\Program Files\聊天\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\QQPlugin.dll]  [N/A, ]
    [D:\Program Files\聊天\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\QRingMng.dll]  [N/A, ]
    [D:\Program Files\聊天\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\聊天\VPortal.dll]  [, 1, 0, 0, 4]
    [D:\Program Files\聊天\QQAvatar.dll]  [N/A, ]
    [D:\Program Files\聊天\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\Program Files\聊天\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [D:\Program Files\聊天\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\BQQApplication.dll]  [N/A, ]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [D:\Program Files\聊天\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\Program Files\聊天\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
[PID: 848][D:\Program Files\聊天\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\Program Files\聊天\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\聊天\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [D:\Program Files\聊天\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [D:\Program Files\聊天\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\Program Files\聊天\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\Program Files\聊天\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 4012][E:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [D:\soft\杀毒工具\安装程序\Windowsmm\Windowsmm\ftcsetup\PassProtect.dll]  [Fygsoft and Microsoft, 2.0.0.92]
    [C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]  [, 1, 3, 0, 0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0x5F00002D)

==================================
隐藏进程
N/A
gototop
 

大哥们,帮忙看看,谢谢了,求你们了
gototop
 

大哥,求你了
gototop
 

随便找了几个.
<C:\WINDOWS\system32\Webrvet.exe><N/A>
\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.dll]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
不光有木马,还有很多流氓软件,手工的话太麻烦了,解决办法,先下载360杀流氓软件,最好再下了NOD32杀毒下,瑞星不敢恭维,杀完了再扫描看下,有无漏网之鱼
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT