瑞星卡卡安全论坛技术交流区系统软件 朋友的扫描报告,现在贴出来.【求助】

1   1  /  1  页   跳转

朋友的扫描报告,现在贴出来.【求助】

朋友的扫描报告,现在贴出来.【求助】

Hijackthis 2006-4-12 renlu-1

Logfile of HijackThis v1.99.1
Scan saved at 20:09:57, on 2006-04-12
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\services32.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\DOCUME~1\user\LOCALS~1\Temp\wt\wt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Rising\Rav\RavTimer.exe
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\WINNT\system32\qcssbl9.exe
C:\WINNT\system32\internat.exe
C:\Syoa\mailalter.exe
C:\WINNT\system32\taskmgr.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\explorer.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.344\HijackThis.exe

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Ins3DT] H:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTimer] C:\Program Files\Rising\Rav\RavTimer.exe
O4 - HKLM\..\Run: [RavTray] C:\Program Files\Rising\Rav\RavTray.exe
O4 - HKLM\..\Run: [RavMon] C:\Program Files\Rising\Rav\RavMon.exe -system
O4 - HKLM\..\Run: [qcsszjcz] C:\WINNT\system32\qcssbl9.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - Startup: 腾讯QQ珊瑚虫版.lnk = D:\QQ\CoralQQ.exe
O4 - Global Startup: IE-BAR.lnk = C:\WINNT\system32\rundll32.exe
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O15 - Trusted IP range: http://10.185.195.27
O16 - DPF: {FC0E4216-5366-43AC-BC8F-FEDD0818F3C7} (Project1.RunExe) - http://10.185.194.250/ncdl/RunExe.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{4D976BC2-70B4-49F4-8B68-7AD9B94F52C7}: NameServer = 10.185.1.5,61.128.128.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{F32194BC-5292-44CF-8809-ACD0347DDCF5}: NameServer = 10.185.1.5,61.128.128.68
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINNT\system32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINNT\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINNT\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\system32\msdxm.ocx
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Alerter - Unknown owner - C:\WINNT\system32\Alerter16.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: services32 (Content List Management Sub System) - Unknown owner - C:\WINNT\services32.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: WintUPp - Unknown owner - C:\DOCUME~1\user\LOCALS~1\Temp\wt\wt.exe


好多木马病毒.

C:\WINNT\services32.exe

C:\DOCUME~1\user\LOCALS~1\Temp\wt\wt.exe

最后编辑2006-04-12 22:55:45
分享到:
gototop
 

O4 - HKLM\..\Run: [qcsszjcz] C:\WINNT\system32\qcssbl9.exe
O4 - HKLM\..\Run: [Ins3DT] H:\INSTALL4\INS3DT.EXE

O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Alerter - Unknown owner - C:\WINNT\system32\Alerter16.exe
O23 - Service: services32 (Content List Management Sub System) - Unknown owner - C:\WINNT\services32.exe
gototop
 

mailalter.exe
这是什么??
gototop
 

mailalter.exe

这是双杨OA办公系统中的信件到达提示.

回一楼的,我认为,

nwprovau.dll (5.1.2600.1106)
包含在软件
名字: Windows XP Home Edition, Deutsch
执照: 商业
信息链接: http://www.microsoft.com/windowsxp/
文件细节
文件道路: C:\WINDOWS\system32 \ nwprovau.dll
文件日期: 2002-08-29 14:00:00
版本: 5.1.2600.1106
文件大小: 137.728 字节
检查和和文件hashes
CRC32: 27CB6F1A
MD5: 20F8 0342 D86E 4373 1A39 FBD5 01EF E8C4
SHA1: F6F3 AA19 CCEC FFD0 A59B F5F9 E98F DBBB 4161 6C36
版本资源信息
公司名称: Microsoft Corporation
文件描述: Client Service f?Ware-Dienstanbieter und DLL zur Authentifizierung
文件操作系统: Windows NT, Windows 2000, Windows XP, Windows 2003
文件类型: Dynamic Link Library (DLL)
文件版本: 5.1.2600.1106
内部名: nwprovau.dll
法律版权: ? Microsoft Corporation. Alle Rechte vorbehalten.
原始的文件名: nwprovau.dll
产品名称: Betriebssystem Microsoft? Windows?
产品版本: 5.1.2600.1106
gototop
 

O23 - Service: services32 (Content List Management Sub System) - Unknown owner - C:\WINNT\services32.exe
特别注意这个
gototop
 

你说得对.
网上的资料说这是病毒.
gototop
 

再见.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT