1   1  /  1  页   跳转

中毒已深,求助!

中毒已深,求助!

最近,我的手提电脑出现了很多问题:
1、经常性在我使用电脑时自动转入待机状态。
2、我用的maxthon和windowsxp自带的IE浏览器(我用的是7.0)经常性自动缩小到屏幕右下角声音图标那一块,但不是普通的最小化或隐藏,双击、单击还是右键选择显示窗口都打不开,只能退出重新启动maxthon或者ie浏览器。
3、经常在我打开maxthon时显示,在上次有不正常关闭的网页--一大堆什么 www.lover.cn之类的网站,一看就知道是垃圾网页(见附件的图)
4、qq医生经常性监测到有盗号木马,杀之不尽。

附件传了一个maxthon启动时的截图,请各位大大帮忙,谢谢!

以下为sreng检测结果:
2008-04-05,01:42:05

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <PPS Accelerator><; C:\Program Files\PPStream\ppsap.exe>  [PPStream Inc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <ATICCC><"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay>  []
    <SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>  [Synaptics, Inc.]
    <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [Synaptics, Inc.]
    <PWRMGRTR><rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor>  [Lenovo Group Limited]
    <BLOG><rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog>  []
    <TPHOTKEY><C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe>  []
    <TpShocks><TpShocks.exe>  [Lenovo, Ltd. and IBM Corporation.]
    <TPKMAPHELPER><C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper>  [Lenovo]
    <EZEJMNAP><C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe>  [Lenovo Group Limited]
    <ACTray><C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe>  [Lenovo]
    <ACWLIcon><C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe>  [Lenovo]
    <SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe>  [Analog Devices, Inc.]
    <SoundMAX><C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray>  [Analog Devices, Inc.]
    <LPManager><C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe>  [Lenovo Group Limited]
    <AMSG><C:\PROGRA~1\THINKV~1\AMSG\amsg.exe>  [LENOVO]
    <PSQLLauncher><"C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup>  [UPEK Inc.]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [Symantec Corporation]
    <Symantec PIF AlertEng><"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll">  []
    <MenuOrder><C:\Program Files\ICBCPe~1\ICBC\BHDC(Personal)\MenuOrder\MenuOrder.exe>  []
    <Microsoft Pinyin IME Migration><C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE /INSTALL>  [Microsoft Corporation]
    <MRT><; ; ; ; "C:\WINDOWS\system32\MRT.exe" /R>  [Microsoft Corporation]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <!AVG Anti-Spyware><; "E:\software\AVG Anti-Spyware-v7.5.1.43\avgas.exe" /minimized>  [GRISOFT s.r.o.]
    <WINSvr32><C:\WINDOWS\WINSvr32.exE>  []
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  []
    <NWEReboot><; ; ; ; ; ;>  []
    <osCheck><; ; "C:\Program Files\Norton AntiVirus\osCheck.exe">  []
    <WangWang><; ; ; "C:\Program Files\Alisoft\WangWang\WangWang.EXE">  []
    <WebThunder><; ; ; ; ; "C:\Program Files\Thunder Network\WebThunder\WebThunder.exe" /autostart>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><LogonUI.EXE>  [Microsoft Corporation]

==================================
启动文件夹
[word]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\word.lnk><N>

==================================
服务
[2BC61902 / 2BC61902]
  <><N/A>
[Ac Profile Manager Service / AcPrfMgrSvc]
  <C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe><N/A>
[Access Connections Main Service / AcSvc]
  <C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe><Lenovo>
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Autodesk Licensing Service / Autodesk Licensing Service]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard]
  <E:\software\AVG Anti-Spyware-v7.5.1.43\guard.exe><GRISOFT s.r.o.>
[Bluetooth Service / btwdins]
  <C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe><Broadcom Corporation.>
[Symantec Event Manager / ccEvtMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon><Symantec Corporation>
[Symantec Lic NetConnect service / CLTNetCnService]
  <"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon><Symantec Corporation>
[Intel(R) PROSet/Wireless Event Log / EvtEng]
  <C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[F66E203A / F66E203A]
  <><N/A>
[ThinkPad PM Service / IBMPMSVC]
  <C:\WINDOWS\system32\ibmpmsvc.exe><N/A>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[IPS 核心服务 / IPSSVC]
  <C:\WINDOWS\system32\IPSSVC.EXE><Lenovo Group Limited>
[Symantec IS Password Validation / ISPwdSvc]
  <"C:\Program Files\Norton AntiVirus\isPwdSvc.exe"><Symantec Corporation>
[LiveUpdate / LiveUpdate]
  <"C:\PROGRA~1\Symantec\LIVEUP~

[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Maxthon; .NET CLR 2.0.50727)

附件附件:

下载次数:777
文件类型:image/pjpeg
文件大小:
上传时间:2008-4-16 10:16:58
描述:
预览信息:EXIF信息



最后编辑2008-04-16 22:55:58.640000000
分享到:
gototop
 

刚刚qq医生又出来了那个盗号木马,
名称为:win32.qqtailmsg.mcdsrvmsgd.a
文件路径:c:\windows\system32\mcdcsrv32_08329.dll
gototop
 

请将日志内容完整复制到txt文本,将txt文本以附件的形式上传,不要直接贴上来!
gototop
 

谢谢,现将日志文件传上,请各位大大指点

附件附件:

下载次数:90
文件类型:application/octet-stream
文件大小:
上传时间:2008-4-16 22:55:58
描述:

gototop
 

引用:
【奋青的贴子】谢谢,现将日志文件传上,请各位大大指点
………………

日志不全,一份完整的SREng日志应该包含以下分隔线中的信息:
-----------------------------------------------------




日期时间

System Repair Engineer 版本
Smallfrogs (http://www.KZTechs.com)

操作系统版本信息 - 用户权限 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描


启动项目
注册表


==================================
启动文件夹


==================================
服务


==================================
驱动程序


==================================
浏览器加载项


==================================
正在运行的进程


==================================
文件关联
.TXT 
.EXE 
.COM 
.PIF 
.REG
.BAT 
.SCR 
.CHM 
.HLP 
.INI 
.INF 
.VBS 
.JS 
.LNK 

==================================
Winsock 提供者


==================================
Autorun.inf


==================================
HOSTS 文件


==================================
进程特权扫描


==================================
API HOOK


==================================
隐藏进程


==================================





-----------------------------------------------------

你可以重新去扫描日志,截图中的所有选项都打勾然后再扫描,扫描完以后把完整的日志复制到txt文本后上传。
gototop
 

根据你提供的日志能看到的问题:
<WINSvr32><C:\WINDOWS\WINSvr32.exE> []
C:\Documents and Settings\All Users\「开始」菜单\程序\启动\word.lnk
C:\WINDOWS\system32\mxcdcsrv16_080329.dll
C:\WINDOWS\system32\mcdcsrv32_080329.dll

[2BC61902 / 2BC61902]
<><N/A>
[F66E203A / F66E203A]
<><N/A>

[]
  {6167F471-EF2B-41DD-A5E5-C26ACDB5C096} <C:\Program Files\Internet Explorer\PLUGINS\WinSys8v.Sys, N/A>
[]
  {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} <C:\Program Files\Internet Explorer\IEXPLORE32.win, N/A>
[]
  {C5E87A05-F463-4841-B19E-DD3EC3862368} <C:\Program Files\Internet Explorer\IEXPLORE32.Sys, N/A>
[]
  {EE12D60D-AD9A-4095-B839-3BE6862679FD} <C:\Program Files\Internet Explorer\IEXPLORE32.Dat, N/A>

另外你同时安装了瑞星、诺顿、AVG,这样会有冲突,建议你保留其中之一,将另外两个卸载掉。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT