瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】大家帮忙啊,郁闷死了.跪谢

1   1  /  1  页   跳转

【求助】大家帮忙啊,郁闷死了.跪谢

【求助】大家帮忙啊,郁闷死了.跪谢

探测到: 病毒 Worm.Win32.Downloader.dq    网址: http://dd.749571.com/bb/ll.exe//PE_Patch//UPack
诊断时间: 2008-01-05  16:56:47
诊断平台: Microsoft Windows XP  Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build:62900.2180
计算机物理内存:1022.42MB - 当前可用内存:593.25MB
100 - 未知 - Process: ssMgr_ccb.exe [StarSec Token Manager] - C:\Program Files\StarSec\ssMgr_ccb.exe
100 - 未知 - Process: raysat_3dsmax8server.exe [] - D:\3D MAX8.0\3dmax8\3dmax\mentalray\satellite\raysat_3dsmax8server.exe
100 - 未知 - Process: PlugServer.exe [PlugServer] - C:\Program Files\StarSec\PlugServer.exe
O2 - 未知 - BHO: (ThunderAtOnce Class) - [迅雷浏览器高级特性支持模块] - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\迅雷\ComDlls\TDAtOnce_Now.dll
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{1E796980-9CC5-11D1-A83F-00C04FC99D61}] - {1E796980-9CC5-11D1-A83F-00C04FC99D61} -
O4 - 未知 - HKLM\..\Run: [amd_dc_opt] [AMD Dual-Core Optimizer] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O23 - 未知 - Service: AVP [Provides protection against computer viruses and spyware, hacker attacks, cyber-crime and spam.] - "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r - (running)
O23 - 未知 - Service: mi-raysat_3dsmax8 [mental ray 3.4 Satellite] - "D:\3D MAX8.0\3dmax8\3dmax\mentalray\satellite\raysat_3dsmax8server.exe" - (running)
O23 - 未知 - Service: PlugServer [PlugServerD] - C:\Program Files\StarSec\PlugServer.exe - (running)
O23 - 未知 - Service: windows_0 [Windows Accounts Driver] -  - (not running)
O23 - 未知 - Service: Yiqilai [一起来音乐助手] - "C:\Program Files\Yiqilai\wmp\YiqilaiLyrics.exe" - (not running)
=======================================
100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 安全 - Process: spoolsv.exe [windows打印任务控制程序,用以打印机就绪。] - C:\WINDOWS\system32\spoolsv.exe
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE
100 - 安全 - Process: RTHDCPL.exe [瑞昱出品的声卡相关程序。] - C:\WINDOWS\RTHDCPL.EXE
100 - 安全 - Process: rundll32.exe [windows rundll32为了需要调用dlls的程序。] - C:\WINDOWS\system32\RunDLL32.exe
100 - 安全 - Process: VM303_STI.EXE [一款摄像头相关程序。] - C:\WINDOWS\VM303_STI.EXE
100 - 安全 - Process: AdskScSrv.exe [autodesk公司相关软件的认证许可服务程序。] - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
100 - 安全 - Process: 360tray.exe [360安全卫士实时监控程序。] - C:\Program Files\360safe\safemon\360Tray.exe
100 - 安全 - Process: safeboxTray.exe [360安全卫士保险箱相关程序。] - D:\360\360Safebox\safeboxTray.exe
100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\WINDOWS\system32\ctfmon.exe
100 - 安全 - Process: nvsvc32.exe [nvidia driver helper service在nvida显卡驱动中被安装。] - C:\WINDOWS\system32\nvsvc32.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k imgsvc
100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\WINDOWS\System32\alg.exe
100 - 安全 - Process: conime.exe [console ime ime输入法控制台软件。] - C:\WINDOWS\system32\conime.exe
100 - 安全 - Process: IEXPLORE.EXE [microsoft internet explorer浏览器用于浏览网页。] - C:\Program Files\Internet Explorer\iexplore.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士相关程序。] - C:\Program Files\360safe\360safe.exe
O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\迅雷\ComDlls\xunleiBHO_Now.dll
O4 - 安全 - HKLM\..\Run: [NvCplDaemon] [是NVIDIA显示卡相关动态链接库文件。] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 安全 - HKLM\..\Run: [nwiz] [是NVidia的Nview特性相关程序。该程序用于用户对其特性进行配置,将桌面扩展到多台显示器上。 ] nwiz.exe /install
O4 - 安全 - HKLM\..\Run: [RTHDCPL] [realtek声卡特性设置软件相关程序。] RTHDCPL.EXE
O4 - 安全 - HKLM\..\Run: [Alcmtr] [一款声卡相关程序。] ALCMTR.EXE
O4 - 安全 - HKLM\..\Run: [NvMediaCenter] [是NVidia显示卡相关文件。] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - 安全 - HKLM\..\Run: [BigDog303] [一款摄像头相关程序。] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera 301PLH
O4 - 安全 - HKLM\..\Run: [TkBellExe] [是Real Networks产品定时升级检测程序。] "realsched.exe"  -osboot
O4 - 安全 - HKLM\..\Run: [WangWang] [淘宝旺旺软件。] "D:\淘宝旺旺\WangWang\WangWang\WangWang.EXE"
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O4 - 安全 - Startup folder: [QQ游戏启动加速程序.lnk] [qq游戏启动加速相关程序。] C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk
O23 - 安全 - Service: Autodesk Licensing Service [Autodesk的服务程序。] - "C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe" - (running)
O23 - 安全 - Service: NVSvc [是NVIDIA显示卡相关程序。] - C:\WINDOWS\system32\nvsvc32.exe - (running)
=======================================


[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322)
最后编辑2008-01-05 17:33:22
分享到:
gototop
 

O31 - 未知 - SEApproved: 无效的CLSID:Shell Extensions for RealOne Player -  -  -  -  - 0 -
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll -  -  -  - 125440 - fd00edb8e782858243cf1469c329ee88
O31 - 未知 - LSA: Security Packages - sv1_0.dll -  -  -  - 0 -
O31 - 未知 - LSA: Security Packages - channel.dll -  -  -  - 0 -
=======================================
O40 - Explorer.EXE - NVIDIA Corporation - C:\WINDOWS\system32\NVRSZHC.DLL - NVIDIA Simplified Chinese language resource library - 253c0aec6300a219a274a60a0800ccbf
O40 - Explorer.EXE -  - C:\WINDOWS\system32\nvshell.dll -  - 4450bbaf1b77f2b87ab9c5ee4e69532c
O40 - RunDLL32.exe - NVIDIA Corporation - C:\WINDOWS\system32\NVRSZHC.DLL - NVIDIA Simplified Chinese language resource library - 253c0aec6300a219a274a60a0800ccbf
=======================================
O41 - 5bdb9lk0 - 5bdb9lk0 - C:\WINDOWS\system32\drivers\5bdb9lk0.sys - (running) -  -  - 8a4996d1cdd11a5466922596c1a755fc
O41 - ahci8086 - ATI Technology AHCI Compatible Controller Driver for Windows family - C:\WINDOWS\system32\drivers\ahci8086.sys - (running) - ATI Technology AHCI Compatible Controller Driver for Windows family - ATI Technologies Inc. - 3162702a838386f7bc6f6b4711044cf2
O41 - CSB6IDE - ServerWorks CSB6 PCI IDE Bus Driver - C:\WINDOWS\system32\drivers\csb6ide.sys - (running) - ServerWorks CSB6 PCI IDE Bus Driver - ServerWorks Corporation - 7a49f7091e79cc364d8df1c6ea845756
O41 - FASTTRAK - Promise FastTrak Series Driver for Win2000 - C:\WINDOWS\system32\drivers\fasttrak.sys - (running) - Promise FastTrak Series Driver for Win2000 - Promise Technology, Inc. - d3a41b9167c11b0fa0cb7c61fc876982
O41 - FTSATA2 - Promise Driver for Windows Server 2003 - C:\WINDOWS\system32\drivers\ftsata2.sys - (running) - Promise Driver for Windows Server 2003 - Promise Technology, Inc. - 65b50b303ff74a5517117ba3d25dbe7f
O41 - IASTOR - Intel Matrix Storage Manager driver - C:\WINDOWS\system32\drivers\iastor.sys - (running) - Intel Matrix Storage Manager driver - Intel Corporation - 580bfec487c55264bfe3d60c3c24eee1
O41 - IGALIVE - IGALIVE - C:\Program Files\IGALIVE\IGALIVE.sys - (running) -  -  - 784bdc2672c2d589cb0337b255a06ec6
O41 - JRAID - JMicron JR036X RAID Driver - C:\WINDOWS\system32\drivers\Jraid.sys - (running) - JMicron JR036X RAID Driver - JMicron Technology Corp. - f64fc8ff777ca76a81c097df7641306d
O41 - klif - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (running) - spuper-ptor - Kaspersky Lab - ade4545fe3dd94d2e44678c745477dab
O41 - M5281 - ALi SATA RAID Controller Driver - C:\WINDOWS\system32\drivers\m5281.sys - (running) - ALi SATA RAID Controller Driver - ALi Corporation - a51cd61975297508d4483fcbf931d86c
O41 - M5289 - ULi SATA RAID Controller Driver - C:\WINDOWS\system32\drivers\m5289.sys - (running) - ULi SATA RAID Controller Driver - ULi Electronics Inc. - e1ca1ea9ad7c8c50ea533829a6854d63
O41 - NVATABUS - NVIDIA? nForce(TM) IDE Performance Driver - C:\WINDOWS\system32\drivers\NVATABUS.SYS - (running) - NVIDIA? nForce(TM) IDE Performance Driver - NVIDIA Corporation - b7fb72492b753930ec70a0f49d04f12f
O41 - SafeBoxKrnl - 360安全卫士 - 保险箱 - D:\360\360Safebox\SafeBoxKrnl.sys - (running) - 360安全卫士 - 保险箱 - 奇虎网 - fa5bed11e5476635922d303fb1730b05
O41 - ZSMC303 - Video streaming and Capture Device Driver - C:\WINDOWS\system32\drivers\usbVM303.sys - (running) - Video streaming and Capture Device Driver - VM -
O41 - A320RAID - Adaptec HostRAID for Ultra320 SCSI - C:\WINDOWS\system32\drivers\a320raid.sys - (not running) - Adaptec HostRAID for Ultra320 SCSI - Adaptec, Inc. - ec8c685100387d4a7a7be2dce922c6d3
O41 - EagleNT - EagleNT - C:\WINDOWS\system32\drivers\EagleNT.sys - (not running) -  -  -
O41 - ENTECH - ENTECH - C:\WINDOWS\system32\drivers\Entech.sys - (not running) -  - EnTech Taiwan - fd9fc82f134b1c91004ffc76a5ae494b
O41 - fhzl - fhzl - C:\WINDOWS\system32\drivers\fhzl.ahc - (not running) -  -  - 3e15afea97d11491999803b698ad3b30
O41 - M5228 - M5228 ATA RAID Controller Driver - C:\WINDOWS\system32\drivers\m5228.sys - (not running) - M5228 ATA RAID Controller Driver - ALi Corporation. - 06c174e5c7845055c3d6317709af6423
O41 - NPF - npf - C:\WINDOWS\system32\drivers\npf.sys - (not running) - npf - CACE Technologies - 2c19036687354db0ed375040afa0d735
O41 - npkcrypt - nProtect KeyCrypt Driver - E:\R2\R2\npkcrypt.sys - (not running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - db56cf603a61bebfe031cfb3c95db816
O41 - npkycryp - npkycryp - C:\WINDOWS\system32\npkycryp.sys - (not running) -  -  -
O41 - ntb20 - ntb20 - C:\WINDOWS\System32\DRIVERS\ntb20.sys - (not running) -  -  -
O41 - SI3112R - Serial ATA RAID miniport driver - C:\WINDOWS\system32\drivers\Si3112r.sys - (not running) - Serial ATA RAID miniport driver - Silicon Image, Inc - c82f9b4993f502361067e3ab61d46f7a
O41 - SI3114R - SATARAID miniport driver - C:\WINDOWS\system32\drivers\Si3114r.sys - (not running) - SATARAID miniport driver - Silicon Image, Inc - d78d5bcf78d38cf846f1f1fdde718acc
O41 - SI3114R5 - SATA SoftRAID 5 miniport driver - C:\WINDOWS\system32\drivers\Si3114r5.sys - (not running) - SATA SoftRAID 5 miniport driver - Silicon Image, Inc - bf4177bfa0397c6a01ed493240318eae
O41 - SI3124 - Serial ATA miniport driver - C:\WINDOWS\system32\drivers\Si3124.sys - (not running) - Serial ATA miniport driver - Silicon Image, Inc. - c48aaff4947d87ebf6c42d9fced3df7a
O41 - SI3124R - SATARAID miniport driver (PRE-RELEASE) - C:\WINDOWS\system32\drivers\Si3124r.sys - (not running) - SATARAID miniport driver (PRE-RELEASE) - Silicon Image, Inc - 0c71855057883e63ca2c19736cbab018
O41 - SI3124R5 - SATA SoftRAID 5 miniport driver - C:\WINDOWS\system32\drivers\Si3124r5.sys - (not running) - SATA SoftRAID 5 miniport driver - Silicon Image, Inc - 085200d2a56c58ad77ef733082cb6ad4
O41 - SI3132 - Serial ATA miniport driver - C:\WINDOWS\system32\drivers\Si3132.sys - (not running) - Serial ATA miniport driver - Silicon Image, Inc. - 6e42ca2af3516cda7f3776a186ca4f78
O41 - SI3132R5 - SATA SoftRAID 5 miniport driver - C:\WINDOWS\system32\drivers\Si3132r5.sys - (not running) - SATA SoftRAID 5 miniport driver - Silicon Image, Inc - 07adf4521fe169623cc13fc8303bb519
O41 - SYMMPI - LSI Logic Fusion-MPT MiniPort Driver (ScsiPort) - C:\WINDOWS\system32\drivers\symmpi.sys - (not running) - LSI Logic Fusion-MPT MiniPort Driver (ScsiPort) - LSI Logic - 10258f3ff6ebaa3e00f1ffb4724764d9
O41 - TesSafe - TesSafe NT Driver - C:\WINDOWS\system32\TesSafe.sys - (not running) - TesSafe NT Driver - TENCENT - 16a95cb4d80459d2e8f40660e33194aa
O41 - VIAMRAID - VIA RAID DRIVER FOR WIN 2000/XP/2003IA32 - C:\WINDOWS\system32\drivers\viamraid.sys - (not running) - VIA RAID DRIVER FOR WIN 2000/XP/2003IA32 - VIA Technologies inc,.ltd - f199939205dccc7836ae5ab8b5dd5e83
O41 - vmscsi - VMware SCSI Controller - C:\WINDOWS\system32\drivers\vmscsi.sys - (not running) - VMware SCSI Controller - VMware, Inc. - cd8a1f04836111dc0e6c0cd904b3c660
探测到: 病毒 Worm.Win32.Downloader.dq网址: http://dd.749571.com/bb/ll.exe//PE_Patch//UPack
怎么杀也杀不掉,每次启动淘宝旺旺都 提示病毒,拒绝病毒,旺旺也关闭了...
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT