瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 病毒名:Trojan.PSW.Win32.....每天杀都杀不完,请帮我看一下,有日志!

12   2  /  2  页   跳转

病毒名:Trojan.PSW.Win32.....每天杀都杀不完,请帮我看一下,有日志!

[PID: 1728 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 348 / SYSTEM][C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe]  [Hewlett-Packard Development Company, L.P., 2, 0, 1, 2]
[PID: 1276 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2092 / LOCAL SERVICE][C:\windows\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\windows\system32\TcpIpDog1.dll]  [N/A, ]
[PID: 2512 / new][C:\PROGRA~1\HPQ\SHARED\HPQTOA~1.EXE]  [, 1, 0, 0, 6]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
[PID: 2836 / new][F:\校园网\Dr.COM宽带认证客户端\ishare_user.exe]  [N/A, ]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
    [C:\windows\system32\TcpIpDog1.dll]  [N/A, ]
[PID: 3000 / new][F:\讯雷1\迅雷\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.4.0.226]
    [F:\讯雷1\迅雷\Program\UpdateDownload.dll]  [N/A, ]
    [F:\讯雷1\迅雷\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
    [F:\讯雷1\迅雷\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [F:\讯雷1\迅雷\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [F:\讯雷1\迅雷\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
    [F:\讯雷1\迅雷\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
    [F:\讯雷1\迅雷\Program\asyn_dns.dll]  [N/A, ]
    [F:\讯雷1\迅雷\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
    [F:\讯雷1\迅雷\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [C:\windows\system32\TcpIpDog1.dll]  [N/A, ]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll]  [YAHOO Corporation Limited, 2, 0, 2, 1003]
    [C:\windows\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [F:\讯雷1\迅雷\Program\iTargetAd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 59]
    [C:\WINDOWS\system32\macromed\flash\Flash85.ocx]  [Macromedia, Inc., 8,5,0,133]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2672 / new][C:\windows\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
[PID: 4024 / new][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\windows\downlo~1\Fgrmvi.dll]  [Tencent, 5, 0, 2, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [, 2, 2, 0, 1050]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  [yahoo! china, 3, 4, 4, 1121]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ysearch.dll]  [Yahoo! China, 3, 2, 5, 1030]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  [Yahoo! China, 3, 0, 5, 1007]
    [C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  [Yahoo! China, 3, 0, 4, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  [Yahoo! China, 3, 0, 4, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YSETTI~1.DLL]  [yahoo! china, 3, 0, 8, 1015]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymailp.dll]  [Yahoo! China, 3, 0, 3, 1009]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymyweb.dll]  [Yahoo! China, 3, 0, 1, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll]  [YAHOO Corporation Limited, 2, 0, 2, 1003]
    [C:\windows\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll]  [yahoo! china, 3, 0, 9, 1011]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 4, 1006]
    [C:\windows\system32\SSup.dll]  [TENCENT, 5, 0, 1, 18]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll]  [Yahoo! China, 3, 1, 7, 1022]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\windows\system32\TcpIpDog1.dll]  [N/A, ]
    [F:\记事本专杀\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrepair.dll]  [Yahoo! China, 3, 0, 9, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasfsks.dll]  [3721.com, 2, 1, 2, 88]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yoptimum.dll]  [Yahoo! China, 3, 0, 2, 1006]
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  [Yahoo! China, 3, 1, 6, 1022]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yxpstyle.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\WINDOWS\system32\macromed\flash\Flash85.ocx]  [Macromedia, Inc., 8,5,0,133]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
gototop
 

[PID: 2080 / new][C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE]  [Microsoft Corporation, 11.0.6560]
    [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll]  [Microsoft Corporation, 11.0.6568]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
    [C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL]  [Microsoft Corporation, 6.0.3275.0]
    [F:\记事本专杀\Rising\Rav\RsPlugIn.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.14]
    [C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll]  [Microsoft Corporation, 5.50.99.2010]
    [C:\Program Files\Microsoft Office\OFFICE11\msostyle.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 1968 / new][C:\windows\notepad.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
[PID: 3400 / new][F:\日志\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 27]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 2, 0, 6, 1009]
    [F:\日志\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\windows\system32\TcpIpDog1.dll]  [N/A, ]

==================================
文件关联
.TXT  Error. [C:\windows\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\windows\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\windows\system32\TcpIpDog1.dll(, N/A)
MSAFD Tcpip [UDP/IP]
    C:\windows\system32\TcpIpDog1.dll(, N/A)
MSAFD Tcpip [RAW/IP]
    C:\windows\system32\TcpIpDog1.dll(, N/A)
RSVP UDP Service Provider
    C:\windows\system32\TcpIpDogR0.dll(, N/A)
RSVP TCP Service Provider
    C:\windows\system32\TcpIpDogR0.dll(, N/A)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 648, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 684, C:\PROGRAM FILES\HPQ\HP WIRELESS ASSISTANT\HP WIRELESS ASSISTANT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 692, C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 692, C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2512, C:\PROGRA~1\HPQ\SHARED\HPQTOA~1.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2836, F:\校园网\DR.COM宽带认证客户端\ISHARE_USER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3000, F:\讯雷1\迅雷\PROGRAM\THUNDER5.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

如果有解决的办法,请详细告之~~我是新手
gototop
 

哦!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT