瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】这倒底是不是流氓或病毒软件呀?

1   1  /  1  页   跳转

【求助】这倒底是不是流氓或病毒软件呀?

【求助】这倒底是不是流氓或病毒软件呀?

2007-5-29 18:06:40我在反病毒区发过贴,但没有人能回答,现在放到此区来看看,我把如贴内容放过来。
每次启动机器后都有一个rundll32.exe的进程,用瑞星卡卡查看进程如下:
[rundll32.exe]
PID = 0x288
CommandLine = rundll32.exe \JOnAS.dll,Service
rundll32.exe
0x1000000
C:\WINNT\system32\rundll32.exe
5.00.2134.1
Microsoft Corporation
Run a DLL as an App
2000-01-10 20:00:00

ntdll.dll
0x77f80000
C:\WINNT\system32\NTDLL.DLL
5.00.2195.7006
Microsoft Corporation
NT Layer DLL
2005-08-16 03:56:12

KERNEL32.dll
0x77e60000
C:\WINNT\system32\KERNEL32.DLL
5.00.2195.7099
Microsoft Corporation
Windows NT BASE API Client DLL
2006-06-21 14:51:46

GDI32.dll
0x77f40000
C:\WINNT\system32\GDI32.DLL
5.00.2195.7073
Microsoft Corporation
GDI Client DLL
2005-12-31 00:15:30

USER32.dll
0x77df0000
C:\WINNT\system32\USER32.DLL
5.00.2195.7032
Microsoft Corporation
Windows 2000 USER API Client DLL
2005-06-03 07:18:06

IMAGEHLP.dll
0x77900000
C:\WINNT\system32\IMAGEHLP.DLL
5.00.2195.6613
Microsoft Corporation
Windows NT Image Helper
2003-06-19 12:05:04

MSVCRT.DLL
0x78000000
C:\WINNT\system32\msvcrt.dll
6.10.9844.0
Microsoft Corporation
Microsoft (R) C Runtime Library
2003-06-19 12:05:04

IMM32.DLL
0x75e00000
C:\WINNT\system32\imm32.dll
5.00.2195.6655
Microsoft Corporation
Windows 2000 IMM32 API Client DLL
2003-06-19 12:05:04

ADVAPI32.DLL
0x796d0000
C:\WINNT\system32\ADVAPI32.DLL
5.00.2195.7038
Microsoft Corporation
Advanced Windows 32 Base API
2005-06-03 07:18:06

RPCRT4.dll
0x786f0000
C:\WINNT\system32\rpcrt4.dll
5.00.2195.7085
Microsoft Corporation
Remote Procedure Call Runtime
2006-04-13 13:16:40

LPK.DLL
0x6c330000
C:\WINNT\system32\lpk.dll
5.00.2195.6692
Microsoft Corporation
Language Pack
2003-06-19 12:05:04

USP10.dll
0x65d20000
C:\WINNT\system32\usp10.dll
1.0325.2195.6692
Microsoft Corporation
Uniscribe Unicode script processor
2003-06-19 12:05:04

这里最让人怀疑的是那个名为JOnAS.dll的文件,它在winnt\temp\目录下,可以用卡卡结束此进程,结束此进程后不会再运行,除非重启,有时瑞星会提示是病毒是不是删除或杀毒,但删除或杀毒一次后,下次重启后又可能会出现瑞星提示。以网上也没找到关于JOnAS.dll文件的有用信息,所以在此贴出来大家帮我看看,谢谢。
最后编辑2007-06-25 13:08:57
分享到:
gototop
 

每次开机后我都手动把此进程结束了,今天开机后此进程变以了,如下:
[rundll32.exe]
PID = 0x278
CommandLine = rundll32.exe "C:\WINNT\TEMP\Gentad\Octopus.dll",Service
rundll32.exe
0x1000000
C:\WINNT\system32\rundll32.exe
5.00.2134.1
Microsoft Corporation
Run a DLL as an App
2000-01-10 20:00:00

ntdll.dll
0x77f80000
C:\WINNT\system32\NTDLL.DLL
5.00.2195.7006
Microsoft Corporation
NT Layer DLL
2005-08-16 03:56:12

KERNEL32.dll
0x77e60000
C:\WINNT\system32\KERNEL32.DLL
5.00.2195.7099
Microsoft Corporation
Windows NT BASE API Client DLL
2006-06-21 14:51:46

GDI32.dll
0x77f40000
C:\WINNT\system32\GDI32.DLL
5.00.2195.7133
Microsoft Corporation
GDI Client DLL
2007-03-06 19:17:16

USER32.dll
0x77df0000
C:\WINNT\system32\USER32.DLL
5.00.2195.7133
Microsoft Corporation
Windows 2000 USER API Client DLL
2007-03-06 19:17:18

IMAGEHLP.dll
0x77900000
C:\WINNT\system32\IMAGEHLP.DLL
5.00.2195.6613
Microsoft Corporation
Windows NT Image Helper
2003-06-19 12:05:04

MSVCRT.DLL
0x78000000
C:\WINNT\system32\msvcrt.dll
6.10.9844.0
Microsoft Corporation
Microsoft (R) C Runtime Library
2003-06-19 12:05:04

IMM32.DLL
0x75e00000
C:\WINNT\system32\imm32.dll
5.00.2195.6655
Microsoft Corporation
Windows 2000 IMM32 API Client DLL
2003-06-19 12:05:04

ADVAPI32.DLL
0x796d0000
C:\WINNT\system32\ADVAPI32.DLL
5.00.2195.7038
Microsoft Corporation
Advanced Windows 32 Base API
2005-06-03 07:18:06

RPCRT4.dll
0x786f0000
C:\WINNT\system32\rpcrt4.dll
5.00.2195.7085
Microsoft Corporation
Remote Procedure Call Runtime
2006-04-13 13:16:40

LPK.DLL
0x6c330000
C:\WINNT\system32\lpk.dll
5.00.2195.6692
Microsoft Corporation
Language Pack
2003-06-19 12:05:04

USP10.dll
0x65d20000
C:\WINNT\system32\usp10.dll
1.0325.2195.6692
Microsoft Corporation
Uniscribe Unicode script processor
2003-06-19 12:05:04

Octopus.dll
0x10000000
C:\WINNT\Temp\Gentad\Octopus.dll



1970-01-01 08:00:00

ole32.dll
0x7cf00000
C:\WINNT\system32\OLE32.DLL
5.00.2195.7059
Microsoft Corporation
Microsoft OLE for Windows
2005-09-05 16:17:35

SHLWAPI.dll
0x70a70000
C:\WINNT\system32\SHLWAPI.DLL
6.00.2800.1907 (xpsp2.070219-1040)
Microsoft Corporation
Shell Light-weight Utility Library
2007-02-19 12:56:54

SHELL32.dll
0x78f90000
C:\WINNT\system32\SHELL32.DLL
5.00.3900.7105
Microsoft Corporation
Windows Shell Common Dll
2006-07-13 15:08:54

COMCTL32.dll
0x71710000
C:\WINNT\system32\comctl32.dll
5.81
Microsoft Corporation
Common Controls Library
2006-08-28 16:44:10

WS2_32.dll
0x74fb0000
C:\WINNT\system32\ws2_32.dll
5.00.2195.6601
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-06-19 12:05:04

WS2HELP.DLL
0x74fa0000
C:\WINNT\system32\ws2help.dll
5.00.2134.1
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2000-01-10 20:00:00

WININET.dll
0x63000000
C:\WINNT\system32\WININET.DLL
6.00.2800.1593
Microsoft Corporation
Internet Extensions for Win32
2007-02-19 13:31:24

CRYPT32.dll
0x79c40000
C:\WINNT\system32\CRYPT32.DLL
5.131.2195.6926
Microsoft Corporation
Crypto API32
2005-06-03 07:18:08

MSASN1.dll
0x773f0000
C:\WINNT\system32\msasn1.dll
5.00.2195.6905
Microsoft Corporation
ASN.1 Runtime APIs
2005-06-03 07:18:08

OLEAUT32.dll
0x77990000
C:\WINNT\system32\OLEAUT32.DLL
2.40.4522
Microsoft Corporation

2003-06-19 12:05:04

VERSION.dll
0x777e0000
C:\WINNT\system32\version.dll
5.00.2195.6623
Microsoft Corporation
Version Checking and File Installation Libraries
2003-06-19 12:05:04

LZ32.DLL
0x75950000
C:\WINNT\system32\lz32.dll
5.00.2195.6611
Microsoft Corporation
LZ Expand/Compress API DLL
2003-06-19 12:05:04

SETUPAPI.dll
0x6d990000
C:\WINNT\system32\SETUPAPI.DLL
5.00.2195.6622
Microsoft Corporation
Windows Setup API
2003-06-19 12:05:04

USERENV.DLL
0x794d0000
C:\WINNT\system32\USERENV.DLL
5.00.2195.7002
Microsoft Corporation
Userenv
2005-06-03 07:18:06

NETAPI32.dll
0x7cea0000
C:\WINNT\system32\NETAPI32.DLL
5.00.2195.7108
Microsoft Corporation
Net Win32 API DLL
2006-08-17 21:14:10

Secur32.dll
0x797b0000
C:\WINNT\system32\secur32.dll
5.00.2195.6695
Microsoft Corporation
Security Support Provider Interface
2003-06-19 12:05:04

NTDSAPI.dll
0x77bd0000
C:\WINNT\system32\ntdsapi.dll
5.00.2195.6666
Microsoft Corporation
NT5DS
2003-06-19 12:05:04

DNSAPI.DLL
0x77960000
C:\WINNT\system32\dnsapi.dll
5.00.2195.7100
Microsoft Corporation
DNS Client API DLL
2006-07-06 19:45:02

WSOCK32.dll
0x74fd0000
C:\WINNT\system32\wsock32.dll
5.00.2195.6603
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-06-19 12:05:04

WLDAP32.DLL
0x77930000
C:\WINNT\system32\WLDAP32.DLL
5.00.2195.7017
Microsoft Corporation
Win32 LDAP API DLL
2005-06-03 07:18:08

NETRAP.dll
0x75150000
C:\WINNT\system32\netrap.dll
5.00.2134.1
Microsoft Corporation
Net Remote Admin Protocol DLL
2000-01-10 20:00:00

SAMLIB.dll
0x750e0000
C:\WINNT\system32\samlib.dll
5.00.2195.6944
Microsoft Corporation
SAM Library DLL
2005-06-03 07:18:24

RASAPI32.DLL
0x774a0000
C:\WINNT\system32\RASAPI32.DLL
5.00.2195.6920
Microsoft Corporation
Remote Access API
2005-06-03 07:18:08

rasman.dll
0x77480000
C:\WINNT\system32\RASMAN.DLL
5.00.2195.6824
Microsoft Corporation
Remote Access Connection Manager
2005-06-03 07:18:08

TAPI32.dll
0x774f0000
C:\WINNT\system32\TAPI32.DLL
5.00.2195.6664
Microsoft Corporation
Microsoft? Windows(TM) Telephony API Client DLL
2003-06-19 12:05:04

RTUTILS.DLL
0x777f0000
C:\WINNT\system32\rtutils.dll
5.00.2168.1
Microsoft Corporation
Routing Utilities
2000-01-10 20:00:00

rsabase.dll
0x7ca00000
C:\WINNT\system32\RSABASE.DLL
5.00.2195.6619
Microsoft Corporation
Microsoft Base Cryptographic Provider (Export Version)
2003-06-19 12:05:04

rnr20.dll
0x77800000
C:\WINNT\system32\RNR20.DLL
5.00.2195.6603
Microsoft Corporation
Windows Socket2 NameSpace DLL
2003-06-19 12:05:04

iphlpapi.dll
0x77300000
C:\WINNT\system32\IPHLPAPI.DLL
5.00.2195.7097
Microsoft Corporation
IP Helper API
2006-05-19 17:17:56

ICMP.dll
0x774e0000
C:\WINNT\system32\icmp.dll
5.00.2134.1
Microsoft Corporation
ICMP DLL
2000-01-10 20:00:00

MPRAPI.dll
0x772e0000
C:\WINNT\system32\mprapi.dll
5.00.2181.1
Microsoft Corporation
Windows NT MP Router Administration DLL
2000-01-10 20:00:00

ACTIVEDS.DLL
0x77370000
C:\WINNT\system32\activeds.dll
5.00.2195.6601
Microsoft Corporation
ADs Router Layer DLL
2003-06-19 12:05:04

ADSLDPC.DLL
0x77340000
C:\WINNT\system32\adsldpc.dll
5.00.2195.6993
Microsoft Corporation
ADs LDAP Provider C DLL
2005-06-03 07:18:08

DHCPCSVC.DLL
0x77320000
C:\WINNT\system32\DHCPCSVC.DLL
5.00.2195.7085
Microsoft Corporation
DHCP Client Service
2006-05-19 17:17:56

winrnr.dll
0x777a0000
C:\WINNT\system32\winrnr.dll
5.00.2160.1
Microsoft Corporation
LDAP RnR Provider DLL
2000-01-10 20:00:00

rasadhlp.dll
0x777b0000
C:\WINNT\system32\rasadhlp.dll
5.00.2195.7098
Microsoft Corporation
Remote Access AutoDial Helper
2006-07-06 19:45:02

msafd.dll
0x74f50000
C:\WINNT\system32\msafd.dll
5.00.2195.6602
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-06-19 12:05:04

wshtcpip.dll
0x74f90000
C:\WINNT\system32\wshtcpip.dll
5.00.2195.6601
Microsoft Corporation
Windows Sockets Helper DLL
2003-06-19 12:05:04


这次JOnAS.dll变成Octopus.dll了,真的晕呀。
gototop
 

没人回答了,我自己顶
gototop
 

那个文件不是在%temp%目录下,是在winnt\temp\目录下(我是2K的操作系统)
gototop
 

谢谢海生,此方法已经试过了,只要把rundll32.exe进程结束后就可以删除这个文件,清空temp目录,临时目录,还有网页缓存目录,但重启后此文件又出来了。
gototop
 

我自己还没贴上来,“Crazy栋栋”倒贴上来了,有意思。此问题我已解决。
gototop
 

我用“超级巡警”在非系统分区找到一个被病毒感染的可执行文件,删掉后此问题就解决了。在这里我要感谢lorise给予我的帮助,再次谢谢他。

在这里我说明一下,因为我之前只用了“超级巡警”扫描了非系统分区,而没有用其它杀毒软件扫描,所以我上面是要强调在非系统分区找到了被病毒感染的可执行文件。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT