瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】Trojan.PSW病毒残害小弟一天了,请各位英雄速速相救!

12   2  /  2  页   跳转

【求助】Trojan.PSW病毒残害小弟一天了,请各位英雄速速相救!


    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [C:\DOCUME~1\admin\LOCALS~1\Temp\~Tm4.tmp.rom]  [N/A, ]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
[PID: 2432][C:\WINDOWS\wsttrs.exe]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\wsttrs.dll]  [N/A, ]
[PID: 2492][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\admin\LOCALS~1\Temp\~Tm4.tmp.rom]  [N/A, ]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
[PID: 2528][D:\Program Files\Logitech\SetPoint\SetPoint.exe]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\system32\KemXML.dll]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\system32\kemutb.dll]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\system32\KemUtil.dll]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\system32\KemWnd.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\SetPointCOM.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\Macros\MacroCore.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\IMHook.dll]  [Logitech Inc., 2.60.606]
    [C:\Program Files\Common Files\Logitech\KhalShared\KhalApi.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\kgame.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\GameHook.dll]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\admin\LOCALS~1\Temp\~Tm4.tmp.rom]  [N/A, ]
    [D:\Program Files\Logitech\SetPoint\LCabHandler.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\Macros\MacroMedia.dll]  [Logitech Inc., 2.42.123]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
[PID: 2752][C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE]  [Logitech Inc., 2.60.570]
    [C:\Program Files\Common Files\Logitech\KhalShared\KHALAPI.DLL]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [C:\Program Files\Common Files\Logitech\KhalShared\KHALITCH.DLL]  [Logitech Inc., 2.60.606]
    [C:\Program Files\Common Files\Logitech\KhalShared\KHALMW.DLL]  [Logitech Inc., 2.60.606]
    [C:\Program Files\Common Files\Logitech\KhalShared\KHALHPP.DLL]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\admin\LOCALS~1\Temp\~Tm4.tmp.rom]  [N/A, ]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
[PID: 3856][C:\DOCUME~1\admin\LOCALS~1\Temp\js.exe]  [N/A, ]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [C:\DOCUME~1\admin\LOCALS~1\Temp\~Tm4.tmp.rom]  [N/A, ]
[PID: 3612][D:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3732][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3148][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\DOWNLO~1\CnsHint.dll]  [3721, 2, 5, 0, 2]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
    [C:\WINDOWS\downlo~1\Oxsoq.dll]  [Tencent, 4, 4, 2, 22]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\WINDOWS\system32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 3, 0]
    [c:\program files\google\googletoolbar2.dll]  [Google Inc., 4, 0, 1020, 3054]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  [Tencent, 4, 4, 2, 22]
    [C:\WINDOWS\system32\ssup.dll]  [TENCENT, 4, 4, 3, 31]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [D:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\CSPYII.IME]  [中文之星, 1, 0, 0, 1]
    [C:\WINDOWS\system32\cspyii.dll]  [N/A, ]
    [C:\WINDOWS\system32\xpsp3res.dll]  [Microsoft Corporation, 5.1.2600.3059 (xpsp_sp2_gdr.070104-0050)]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
[PID: 2000][d:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.4.0.226]
    [d:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [d:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
    [d:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [d:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [d:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [N/A, ]
    [d:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
    [d:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [d:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
    [d:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [d:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 11]
    [d:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll]  [ , 2, 3, 0, 37]
    [d:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 10]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.0.3]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [d:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 59]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  [Tencent, 4, 4, 2, 22]
    [C:\WINDOWS\system32\MFPlat.DLL]  [Microsoft Corporation, 11.0.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\WMVDECOD.dll]  [Microsoft Corporation, 11.0.5358.4827 (WMP_11.060509-2009)]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 3328][D:\Program Files\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\downlo~1\Bium.dll]  [Tencent, 4, 4, 2, 30]
    [D:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.60.606]
    [D:\Program Files\Rising\KakaToolBar\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

先谢过6楼的英雄了!
多谢阿!
gototop
 

这个病毒现在每2-3分钟就报出来一组!太恶心了!
请各位帮忙阿
gototop
 

各位老大,帮忙看看咋解决阿
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT