瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 紧急求助:c:\windows\SVCHOST.exe无法删除!!!

12   2  /  2  页   跳转

紧急求助:c:\windows\SVCHOST.exe无法删除!!!

[PID: 3420][C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe]  [N/A, N/A]
    [C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll]  [N/A, N/A]
    [C:\Program Files\ThinkPad\ConnectUtilities\ACGUIHlpr.dll]  [N/A, N/A]
    [C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll]  [N/A, N/A]
    [C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll]  [N/A, N/A]
    [C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgr.dll]  [N/A, N/A]
    [C:\Program Files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll]  [N/A, N/A]
    [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\GUIHlprRes.dll]  [Lenovo, 4, 0, 0, 0]
    [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\IconRes.dll]  [Lenovo, 4, 0, 0, 0]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 3768][C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe]  [Lenovo Group Limited, 3,10,7,0]
[PID: 3952][C:\WINDOWS\System32\DLA\DLACTRLW.EXE]  [Sonic Solutions, 5.20.09a]
    [C:\WINDOWS\system32\DLAAPI_W.DLL]  [Sonic Solutions, 5.20.09a]
    [C:\WINDOWS\System32\DLA\DLACResW.dll]  [Sonic Solutions, 5.20.09a]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 3656][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
    [C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 4, 1, 14]
[PID: 3932][C:\Program Files\Windows Defender\MSASCui.exe]  [Microsoft Corporation, 1.1.1593.0]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 4056][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  [Symantec Corporation, 104.0.11.1]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL]  [Symantec Corporation, 104.0.11.1]
    [C:\WINDOWS\system32\SYMREDIR.DLL]  [Symantec Corporation, 6.0.4.402]
    [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Symantec AntiVirus\SavEmail.dll]  [Symantec Corporation, 10.1.5.5000]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2532][C:\PROGRA~1\SYMANT~1\vptray.exe]  [Symantec Corporation, 10.1.5.5000]
    [C:\Program Files\Common Files\Symantec Shared\ccL40.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  [Symantec Corporation, 9.7.2.3]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Common Files\Symantec Shared\ccAlert.dll]  [Symantec Corporation, 104.0.11.1]
    [C:\Program Files\Symantec AntiVirus\Cliproxy.dll]  [Symantec Corporation, 10.1.5.5000]
    [C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL]  [Symantec Corporation, 10.1.5.5000]
    [C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  [Symantec Corporation, 104.0.11.1]
    [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  [Symantec Corporation, 10.1.5.5000]
    [C:\WINDOWS\system32\nts.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINDOWS\system32\cba.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINDOWS\system32\MsgSys.dll]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\WINDOWS\system32\PDS.DLL]  [LANDesk Software Ltd., 6.12.0.142 E]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 4, 1, 14]
[PID: 2952][C:\Program Files\Lenovo\Client Security Solution\cssauth.exe]  [Lenovo Group Limited, 7.00.0052.00]
    [C:\Program Files\Lenovo\Client Security Solution\cssuserdatadispatcher.dll]  [Lenovo Group Limited, 7.00.0051.00]
    [C:\Program Files\Lenovo\Client Security Solution\csswait.dll]  [Lenovo Group Limited, 7.00.0051.00]
    [C:\Program Files\Common Files\Lenovo\tvt_banner.dll]  [Lenovo Group Limited, 1.10.0051.00]
    [C:\Program Files\Lenovo\Client Security Solution\cssdlgpwentry.dll]  [Lenovo Group Limited, 7.00.0051.00]
    [C:\Program Files\Lenovo\Client Security Solution\dlganswerprompt.dll]  [Lenovo Group Limited, 7.00.0051.00]
    [C:\Program Files\Lenovo\Client Security Solution\tvttsp.dll]  [Lenovo, 1,1,3,006]
    [C:\Program Files\Lenovo\Client Security Solution\tcsrpc.dll]  [Lenovo, 1,1,3,006]
    [C:\Program Files\Common Files\Lenovo\tvt_res.dll]  [Lenovo Group Limited, 1.10.0051.00]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 3192][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2144][C:\Program Files\Digital Line Detect\DLG.exe]  [BVRP Software, 1, 0, 0, 1]
    [C:\Program Files\Digital Line Detect\BVRPDIAG.dll]  [BVRP Software, 1.0]
    [C:\WINDOWS\system32\MdmXSdk.dll]  [Conexant, 1.0.2.010]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1368][D:\Program Files\Tencent\TT\TCPlus.exe]  [腾讯公司, 1, 0, 0, 5]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [D:\Program Files\Tencent\TT\QQDownload.dll]  [Tencent Technology (Shenzhen) Company Limited, 1, 0, 101, 28]
    [D:\Program Files\Tencent\TT\TNProxy.dll]  [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 60]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 5664][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  [Tencent, 4, 1, 6, 61]
    [C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll]  [Lenovo Group Limited, 2.0.0]
    [C:\Program Files\Lenovo\Client Security Solution\tvt_passwordmanager.dll]  [Lenovo Group Limited, 2.0.0]
    [C:\Program Files\Common Files\Lenovo\tvt_banner.dll]  [Lenovo Group Limited, 1.10.0051.00]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [C:\WINDOWS\system32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5091]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 4, 1, 14]
    [C:\Program Files\TENCENT\Adplus\SSAddr1.dll]  [Tencent, 4, 4, 1, 14]
gototop
 

[PID: 5708][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 448][C:\WINDOWS\SVCHOST.EXE]  [N/A, N/A]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 5756][D:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5, 5, 3, 264]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [D:\Program Files\Thunder Network\Thunder\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 14]
    [D:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 12, 2, 42]
    [D:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 12, 2, 42]
    [D:\Program Files\Thunder Network\Thunder\Program\iTargetAD.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 13]
    [D:\Program Files\Thunder Network\Thunder\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 8]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [C:\WINDOWS\system32\Macromed\Common\SwSupport.dll]  [Macromedia, Inc., 10.1r11]
    [D:\Program Files\Thunder Network\Thunder\Components\DiagnoseHelper\DiagnoseHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
    [D:\Program Files\Thunder Network\Thunder\Components\PortVerify\PortVerify.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [D:\Program Files\Thunder Network\Thunder\Components\ExplorerHelper\ExplorerHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [D:\Program Files\Thunder Network\Thunder\Components\DTAG\DTAG.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [D:\Program Files\Thunder Network\Thunder\Program\LiveUpdate.dll]  [, 1, 0, 1, 16]
    [D:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 15]
    [d:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed08.dll]  [ , 3, 2, 0, 63]
    [D:\Program Files\Thunder Network\Thunder\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 13]
    [D:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 43]
    [D:\Program Files\Thunder Network\Thunder\Components\Search\XLSearch.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 6]
    [D:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 13]
    [D:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VPSHELL.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Thunder Network\Thunder\Components\VPSHELL\VideoPicture.dll]  [XunLei, 1, 0, 0, 1]
    [D:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 2, 0, 0, 24]
    [D:\Program Files\Thunder Network\Thunder\Plugins\TingTing\TingTing.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 12]
    [C:\Program Files\TENCENT\Adplus\SSAddr1.dll]  [Tencent, 4, 4, 1, 14]
    [D:\Program Files\Thunder Network\Thunder\Plugins\BhoAdv\bho_adv.dll]  [深圳市迅雷网络技术有限公司, 1.0.1.0]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
[PID: 3860][D:\Download\Temp\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 4, 1, 14]
    [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.5.17.20 14Feb06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
gototop
 

文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
[D:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
[E:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================


gototop
 

发完日志了,现在正在用windows live onecare扫描,发现了1个项目,我用winrar打开windows目录看到c:\windows\SVCHOST.exe已显示为被隔离的木马程序(比较欣慰,但不知道能不能彻底清除干净……)
gototop
 

楼上的,不行啊!!!现在连隐藏文件夹看都看不到了。安全模式下根本删不掉。清理助手能检测出来,清除了以后,只要一打开资源管理器,无论双击还是右键打开,都又再次检测出现那几个程序啊!!!C,D,E盘隐藏文件Autorun.inf,RavMon.exe也是删了又生!!!
难道得重装甚至格式化所有的分区???
gototop
 

搞好了,得先关闭所有分区的还原监视,然后再删除上面兄弟们说的那些项目,就可以了。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT