瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】WEIN32服务中被放了木马,高手看下怎么删,有日志,在线等。感谢

1   1  /  1  页   跳转

【求助】WEIN32服务中被放了木马,高手看下怎么删,有日志,在线等。感谢

【求助】WEIN32服务中被放了木马,高手看下怎么删,有日志,在线等。感谢

知道有木马,就是不知道怎么删,伤心哭泣啊,看下吧,帮忙啊兄弟们。
[CODE]

2007-02-13,22:10:31

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <RegBar><regsvr32.exe /u C:\progra~1\blogmark\bocaitoolbar.dll /s /i /n>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <IgfxTray><C:\WINDOWS\System32\igfxtray.exe>  [(Verified)Intel Corporation]
    <HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe>  [(Verified)Intel Corporation]
    <PmProxy><C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe>  [adi]
    <00THotkey><C:\WINDOWS\System32\00THotkey.exe>  [东芝公司]
    <000StTHK><000StTHK.exe>  [N/A]
    <LTSMMSG><LTSMMSG.exe>  [LT]
    <Tpwrtray><TPWRTRAY.EXE>  [东芝公司]
    <TFNF5><TFNF5.exe>  [Toshiba Corp.]
    <Apoint><C:\Program Files\Apoint2K\Apoint.exe>  [(Verified)Alps Electric Co., Ltd.]
    <TouchED><C:\Program Files\TOSHIBA\TouchED\TouchED.Exe>  [东芝公司]
    <Drag'n Drop CD+DVD><C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp>  [N/A]
    <MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <runeip><C:\Program Files\Rising\KakaToolBar\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start>  [奇虎网]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Updatenm]
    <WinlogonNotify: Updatenm><upern.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xyzDown]
    <WinlogonNotify: xyzDown><xyzDown.dll>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Logical Disk Manager / dmserver][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\pwkbypkr.d1l><N/A>
[DVD-RAM_Service / DVD-RAM_Service][Running/Auto Start]
  <C:\WINDOWS\System32\DVDRAMSV.exe><Matsushita Electric Industrial Co., Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
  <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
最后编辑2007-02-14 10:13:42
分享到:
gototop
 

[Logical Disk Manager / dmserver][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\pwkbypkr.d1l><N/A>
就是这个,看下怎么删,详细说名一下,偶是小虾米,谢谢
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT