瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 【原创】如何用Procexp和Autoruns工具识别与删除木马程序
我问我问 - 2005-11-1 22:24:00
ding
BlackStone - 2005-11-2 11:49:00
引用:
【linzh9286的贴子】楼主,您好!
关于ProcessExplorerNt.zip软件,好像它针对不同系统有不同版本。我想问一下:
如何确定自己的系统是32位、还是64位呢(我的是XP+SP2)?可以在系统哪里可以看到吗?
...........................


ProcessExplorerNt.zip从字面上看好像是运行在NT系列的操作系统上,其实不然,它
可以运行在不同WIN32操作系统,同时可以运行在64位操作系统。之所以叫ProcessExplorerNt.zip,是因为作者早期的工具运行是分系统的(不同的系统要运行不同的程序,因为各个系统的驱动文件是不同的)。

Procexp多系统运行原理:Procexp将驱动文件和运行在64位的程序打包到自身的资源中,当运行,首先判断操作系统版本,不同的操作系统版本加载不同的驱动文件,若系统是64操作系统则将资源中的64位procexp二进制文件释放出来,并启动它。

E文好的可以去作者的网站http://www.sysinternals.com/Blog/看,哪里有关于这方面的BLOG
人健人爱 - 2005-11-4 13:55:00
哈哈,楼主的方法我早就再用了,杀木马还是手动最管用
人健人爱 - 2005-11-4 13:58:00
顺便说一句,瑞星2006版防火墙可查看自动启动项,功能大致跟Autoruns相当,有兴趣的朋友可去试试
小学生x号 - 2005-11-4 19:04:00
学习了
谢谢搂主
0秋色0 - 2005-11-4 21:41:00
好复杂。。。
BlackStone - 2005-11-5 9:25:00
引用:
【王健的贴子】顺便说一句,瑞星2006版防火墙可查看自动启动项,功能大致跟Autoruns相当,有兴趣的朋友可去试试
...........................


瑞星2006版防火墙只针对一般的启动项,对服务,Explorer、IExplorer的扩展启动项没有提及
灵心飞雪 - 2005-11-7 18:50:00
楼主!我的电脑启动后会在记事本里跳出
[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787
哪里出问题了 ~~~怎么办啊
神无 - 2005-11-7 19:02:00
谢谢楼主,收下了,欢迎多多发表这样的帖子。又学两招。
3253652 - 2005-11-7 20:40:00
我晕,大哥,能不能告诉我,你的QQ号呀~~~~我看得头都大了~~
BlackStone - 2005-11-8 10:53:00
引用:
【3253652的贴子】我晕,大哥,能不能告诉我,你的QQ号呀~~~~我看得头都大了~~
...........................


有啥问题?
BlackStone - 2005-11-8 10:56:00
在使用procexp和Autoruns工具过程中遇到的问题可以直接把问题贴上来
灵心飞雪 - 2005-11-8 17:49:00
每次开机都这样.怎么办啊
灵心飞雪 - 2005-11-8 19:13:00
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

+ C:\WINDOWS\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\windows\system32\userinit.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ EXPLORER.EXEWindows ExplorerMicrosoft Corporationc:\windows\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ assistseAssistSettingyahooc:\program files\3721\assistse.exe

+ IMJPMIG8.1Microsoft IMEMicrosoft Corporationc:\windows\ime\imjp8_1\imjpmig.exe

+ KernelFaultCheckWindows Error Reporting Dump Reporting ToolMicrosoft Corporationc:\windows\system32\dumprep.exe

+ mmskd:\瑞星\木马杀客\mmsk.exe

+ MSPY2002c:\windows\system32\ime\pintlgnt\imscinst.exe

+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ NvMediaCenterNVIDIA Media Center LibraryNVIDIA Corporationc:\windows\system32\nvmctray.dll

+ nwizNVIDIA nView Wizard, Version 62.11 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ PHIME2002A微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe

+ PHIME2002ASync微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising
灵心飞雪 - 2005-11-8 19:14:00
Technology Corporation Limitedd:\瑞星\rising\rfw\rfwmain.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ ctfmon.exeCTF LoaderMicrosoft Corporationc:\windows\system32\ctfmon.exe

HKLM\System\CurrentControlSet\Services

+ Alerter通知所选用户和计算机有关系统管理级警报。如果服务停止,使用管理警报的程序将不会受到它们。如果此服务被禁用,任何直接依赖它的服务都将不能启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ ASUSKeyboardServiceASUS Keyboard Service ASUSTeK COMPUTER INC.c:\windows\asuskbservice.exe

+ AudioSrv管理基于 Windows 的程序的音频设备。如果此服务被终止,音频设备及其音效将不能正常工作。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ Browser维护网络上计算机的更新列表,并将列表提供给计算机指定浏览。如果服务停止,列表不会被更新或维护。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ CryptSvc提供三种管理服务: 编录数据库服务,它确定 Windows 文件的签字; 受保护的根服务,它从此计算机添加和删除受信根证书机构的证书;和密钥(Key)服务,它帮助注册此计算机获取证书。如果此服务被终止,这些管理服务将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ DcomLaunch为 DCOM 服务提供加载功能。Microsoft Corporationc:\windows\system32\svchost.exe

+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\windows\system32\svchost.exe

+ dmserver监测和监视新硬盘驱动器并向逻辑磁盘管理器管理服务发送卷的信息以便配置。如果此服务被终止,动态磁盘状态和配置信息会过时。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ Dnscache为此计算机解析和缓冲域名系统 (DNS) 名称。如果此服务被停止,计算机将不能解析 DNS 名称并定位 Active Directory 域控制器。如果此服务被禁用,任何明确依赖它的服务将不能启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ ERSvc服务和应用程序在非标准环境下运行时允许错误报告。Microsoft Corporationc:\windows\system32\svchost.exe

+ Eventlog启用在事件查看器查看基于 Windows 的程序和组件颁发的事件日志消息。无法终止此服务。Microsoft Corporationc:\windows\system32\services.exe

+ helpsvc启用在此计算机上运行帮助和支持中心。如果停止服务,帮助和支持中心将不可用。如果禁用服务,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ lanmanserver支持此计算机通过网络的文件、打印、和命名管道共享。如果服务停止,这些功能不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ lanmanworkstation创建和维护到远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\windows\system32\svchost.exe

+ NVSvcASUS Driver Helper ServiceNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ PlugPlay使计算机在极少或没有用户输入的情况下能识别并适应硬件的更改。终止或禁用此服务会造成系统不稳定。Microsoft Corporationc:\windows\system32\services.exe
灵心飞雪 - 2005-11-8 19:15:00
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\windows\system32\lsass.exe

+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\windows\system32\lsass.exe

+ RemoteRegistry使远程用户能修改此计算机上的注册表设置。如果此服务被终止,只有此计算机上的用户才能修改注册表。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedd:\瑞星\rising\rfw\rfwsrv.exe

+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\windows\system32\svchost.exe

+ RsCCenterCCenterrisingd:\瑞星\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.d:\瑞星\rising\rav\ravmond.exe

+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\windows\system32\lsass.exe

+ Schedule使用户能在此计算机上配置和制定自动任务的日程。如果此服务被终止,这些任务将无法在日程时间里运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ seclogon启用替换凭据下的启用进程。如果此服务被终止,此类型登录访问将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\windows\system32\svchost.exe

+ SharedAccess为家庭和小型办公网络提供网络地址转换、寻址、名称解析和/或入侵保护服务。Microsoft Corporationc:\windows\system32\svchost.exe

+ ShellHWDetection为自动播放硬件事件提供通知。Microsoft Corporationc:\windows\system32\svchost.exe

+ SoundMAX Agent Service (default)SoundMAX service agent componentAnalog Devices, Inc.c:\program files\analog devices\soundmax\smagent.exe

+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\windows\system32\spoolsv.exe

+ srservice执行系统还原功能。 要停止服务,请从“我的电脑”的属性中的系统还原选项卡关闭系统还原Microsoft Corporationc:\windows\system32\svchost.exe

+ Themes为用户提供使用主题管理的经验。Microsoft Corporationc:\windows\system32\svchost.exe

+ TrkWks在计算机内 NTFS 文件之间保持链接或在网络域中的计算机之间保持链接。Microsoft Corporationc:\windows\system32\svchost.exe

+ UMWdf启用 Windows 用户模式驱动程序。Microsoft Corporationc:\windows\system32\wdfmgr.exe

+ W32Time维护在网络上的所有客户端和服务器的时间和日期同步。如果此服务被停止,时间和日期的同步将不可用。如果此服务被禁用,任何明确依赖它的服务都将不能启动。

Microsoft Corporationc:\windows\system32\svchost.exe

+ WebClient使基于 Windows 的程序能创建、访问和修改基于 Internet 的文件。如果此服务被终止,将会失去这些功能。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ winmgmt提供共同的界面和对象模式以便访问有关操作系统、设备、应用程序和服务的管理信息。如果此服务被终止,多数基于 Windows 的软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ wuauserv允许下载并安装 Windows 更新。如果此服务被禁用,计算机将不能使用 Windows Update 网站的自动更新功能。Microsoft Corporationc:\windows\system32\svchost.exe

+ WZCSVC为您的 802.11 适配器提供自动配置Microsoft Corporationc:\windows\system32\svchost.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Internet ExplorerWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe

+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\windows\system32\ie4uinit.exe

+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe

+ Microsoft Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationc:\windows\inf\unregmp2.exe

+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll

+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll

+ Outlook ExpressWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe

+ Themes SetupMicrosoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe

+ Windows Messenger 4.7ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll

+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe

+ 通讯簿 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe

+ 浏览器自定义组件Microsoft Internet Explorer Customization DLLMicrosoft Corporationc:\windows\system32\iedkcs32.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ CDBurnWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ PostBootReminderWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ SysTraySystray shell service objectMicrosoft Corporationc:\windows\system32\stobject.dll

+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

+ Windows木马清道夫Com组件菜单Fygsoft and Microsoftd:\瑞星\mumazhongjiezhe\commenu.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ 金山毒霸File not found: C:\KAV6\KAVEXT.DLL

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ {66742402-F9B9-11D1-A202-0000F81FEDEE}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ BandIE ClassBaiduBar ModuleBaidu.com, Inc.c:\program files\baidu\bar\baidubar.dll

+ DragSearch BHODragSearchc:\program files\yisou\yisoub.dll

+ NTIECatcher ClassNet Transport IE Helper ModuleXic:\program files\nettransport 2\ntiehelper.dll

+ ThunderIEHelper Classxunleibho BHOc:\windows\system32\xunleibho_v8.dll

+ 超级兔子上网精灵File not found: C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL

+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ coolbarCoolBar3721c:\program files\3721\assist\asbar.dll

+ shdocvw.dllShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ 超级兔子上网精灵File not found: C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL

+ 金山毒霸安全助手金山毒霸安全助手金山软件股份有限公司c:\program files\kos\kosiebar.dll

+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll

+ 一搜File not found: C:\PROGRA~1\YiSou\yisou.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ MessengerWindows MessengerMicrosoft Corporationc:\program files\messenger\msmsgs.exe

+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1

+ 豪杰超级解霸V8c:\program files\herov8\sthsdvd.exe

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 手机短信File not found: http://sms.3721.com/ie/index.htm

+ 微软File not found: http://www.microsoft.com/china/index.htm

+ 雅虎助手File not found: http://cn.zs.yahoo.com/?source=Cns

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\windows\system32\autochk.exe
灵心飞雪 - 2005-11-8 19:16:00
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\windows\system32\ntsd.exe

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\windows\system32\advapi32.dll

+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\windows\system32\comdlg32.dll

+ gdi32GDI Client DLLMicrosoft Corporationc:\windows\system32\gdi32.dll

+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\windows\system32\imagehlp.dll

+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\windows\system32\kernel32.dll

+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\windows\system32\lz32.dll

+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\ole32.dll

+ oleaut32Microsoft Corporationc:\windows\system32\oleaut32.dll

+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\windows\system32\olecli32.dll

+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olecnv32.dll

+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\windows\system32\olesvr32.dll

+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olethk32.dll

+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\windows\system32\rpcrt4.dll

+ shell32Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\windows\system32\url.dll

+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll

+ user32Windows XP USER API Client DLLMicrosoft Corporationc:\windows\system32\user32.dll

+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\windows\system32\version.dll

+ wininetInternet Extensions for Win32Microsoft Corporationc:\windows\system32\wininet.dll

+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\windows\system32\wldap32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ cscdllOffline Network AgentMicrosoft Corporationc:\windows\system32\cscdll.dll

+ ScCertPropCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ ScheduleCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ termsrvCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ wlballoonCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

HKCU\Control Panel\Desktop\Scrnsave.exe

+ boinc.scrBOINC ScreensaverSpace Sciences Laboratoryc:\windows\boinc.scr

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{343AA736-7AAC-436A-8F21-B8CE7D7AD866}] DATAGRAM 6Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{343AA736-7AAC-436A-8F21-B8CE7D7AD866}] SEQPACKET 6Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{46727CA6-30E3-44EF-A057-223C606DDFEB}] DATAGRAM 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{46727CA6-30E3-44EF-A057-223C606DDFEB}] SEQPACKET 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{BFD1F7EA-E511-4967-BD93-3C758ED25BC1}] DATAGRAM 7Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{BFD1F7EA-E511-4967-BD93-3C758ED25BC1}] SEQPACKET 7Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{BC91383F-FE1E-4340-8283-1551FCC95135}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{BC91383F-FE1E-4340-8283-1551FCC95135}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{E82F6258-72B2-4729-A2DD-DAE3B931FCAA}] DATAGRAM 8Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{E82F6258-72B2-4729-A2DD-DAE3B931FCAA}] SEQPACKET 8Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{F4A691D2-4B5D-4E8C-B8F5-BB8F2FABCAD0}] DATAGRAM 9Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{F4A691D2-4B5D-4E8C-B8F5-BB8F2FABCAD0}] SEQPACKET 9Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_{782A64E0-9828-4219-AF7A-EBDCF6577CD3}] DATAGRAM 10Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_{782A64E0-9828-4219-AF7A-EBDCF6577CD3}] SEQPACKET 10Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_{CB99F0F4-0456-42AC-9501-EDF210060089}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\Nbf_{CB99F0F4-0456-42AC-9501-EDF210060089}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{0024B411-2542-4991-8217-5656E70A92F2}] DATAGRAM 12Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{0024B411-2542-4991-8217-5656E70A92F2}] SEQPACKET 12Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{67BB0C1D-7FF1-4963-9B1A-B3EC223E9402}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{67BB0C1D-7FF1-4963-9B1A-B3EC223E9402}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{782A64E0-9828-4219-AF7A-EBDCF6577CD3}] DATAGRAM 11Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{782A64E0-9828-4219-AF7A-EBDCF6577CD3}] SEQPACKET 11Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{CB99F0F4-0456-42AC-9501-EDF210060089}] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{CB99F0F4-0456-42AC-9501-EDF210060089}] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E0D2A29A-E6CA-4BA5-8EB9-E8B7C2D1BB07}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E0D2A29A-E6CA-4BA5-8EB9-E8B7C2D1BB07}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E190B647-3BCE-4A54-8FFA-402289118FDB}] DATAGRAM 13Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E190B647-3BCE-4A54-8FFA-402289118FDB}] SEQPACKET 13Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll

+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\windows\system32\cnbjmon.dll

+ Local PortLocal Spooler DLLMicrosoft Corporationc:\windows\system32\localspl.dll

+ PJL Language MonitorPJL Language monitorMicrosoft Corporationc:\windows\system32\pjlmon.dll

+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\windows\system32\tcpmon.dll

+ USB MonitorStandard Dynamic Printing Port Monitor DLLMicrosoft Corporationc:\windows\system32\usbmon.dll
灵心飞雪 - 2005-11-8 19:18:00
快晕了,谢谢楼主哦
BlackStone - 2005-11-8 19:28:00
太多了

用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)
灵心飞雪 - 2005-11-8 19:39:00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ assistseAssistSettingyahooc:\program files\3721\assistse.exe

+ mmskd:\瑞星\木马杀客\mmsk.exe

+ MSPY2002c:\windows\system32\ime\pintlgnt\imscinst.exe

+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ NvMediaCenterNVIDIA Media Center LibraryNVIDIA Corporationc:\windows\system32\nvmctray.dll

+ nwizNVIDIA nView Wizard, Version 62.11 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedd:\瑞星\rising\rfw\rfwmain.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

HKLM\System\CurrentControlSet\Services

+ ASUSKeyboardServiceASUS Keyboard Service ASUSTeK COMPUTER INC.c:\windows\asuskbservice.exe

+ NVSvcASUS Driver Helper ServiceNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedd:\瑞星\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterrisingd:\瑞星\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.d:\瑞星\rising\rav\ravmond.exe

+ SoundMAX Agent Service (default)SoundMAX service agent componentAnalog Devices, Inc.c:\program files\analog devices\soundmax\smagent.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ 金山毒霸File not found: C:\KAV6\KAVEXT.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ BandIE ClassBaiduBar ModuleBaidu.com, Inc.c:\program files\baidu\bar\baidubar.dll

+ DragSearch BHODragSearchc:\program files\yisou\yisoub.dll

+ NTIECatcher ClassNet Transport IE Helper ModuleXic:\program files\nettransport 2\ntiehelper.dll

+ ThunderIEHelper Classxunleibho BHOc:\windows\system32\xunleibho_v8.dll

+ 超级兔子上网精灵File not found: C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL

+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ coolbarCoolBar3721c:\program files\3721\assist\asbar.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ 超级兔子上网精灵File not found: C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL

+ 金山毒霸安全助手金山毒霸安全助手金山软件股份有限公司c:\program files\kos\kosiebar.dll

+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll

+ 一搜File not found: C:\PROGRA~1\YiSou\yisou.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1

+ 豪杰超级解霸V8c:\program files\herov8\sthsdvd.exe

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 手机短信File not found: http://sms.3721.com/ie/index.htm

+ 微软File not found: http://www.microsoft.com/china/index.htm

+ 雅虎助手File not found: http://cn.zs.yahoo.com/?source=Cns

HKCU\Control Panel\Desktop\Scrnsave.exe

+ boinc.scrBOINC ScreensaverSpace Sciences Laboratoryc:\windows\boinc.scr

灵心飞雪 - 2005-11-8 19:46:00
还有我不IE浏览器不能用了
打开后有框,说....加载项遇到故障需要关闭....
我现在用腾讯的了
BlackStone - 2005-11-8 20:10:00
从日志中未发现异常
去http://forum.ikaka.com/topic.asp?board=28&artid=7386171
把问题在那里描述一下
灵心飞雪 - 2005-11-8 20:34:00
哦,
1.开机后就会自动出来一个记事本里面有一窜英文.对后面的操作没影响,我想问问是什么意思,怎样消除.
2.IE浏览器打开网址后点击其他联接时会出现一个框:Internet Explorer已经遇到加载项故障并且需要关闭.之后就没法使用了

是不是和病毒有关.怎么修复~~~
BlackStone - 2005-11-9 9:04:00
1)看机启动后不要关闭那个记事本,用Procexp看看是那个进程运行的Notepad.exe

2)用Autoruns取消IE的插件试试
ken23 - 2005-11-10 20:48:00
太复杂了啊
眼都看花了啊
阿蛮 - 2005-11-14 23:42:00
你好!我刚下载了最新版的,不大会用.请帮我看下日志谢谢~
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ KAVPersonal50Kaspersky Anti-Virus GUI Part(Not verified) Kaspersky Labd:\program files\kaspersky anti-virus personal\kav.exe

HKLM\System\CurrentControlSet\Services

+ kavsvcKaspersky Anti-Virus Service(Not verified) Kaspersky Labd:\program files\kaspersky anti-virus personal\kavsvc.exe

+ NVSvcNVIDIA Driver Helper Service, Version 40.72(Not verified) NVIDIA Corporationd:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall Service(Not verified) Beijing Rising Technology Corporation Limitedd:\program files\rising\rfw\rfwsrv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Desktop ExplorerNVIDIA Desktop Explorer, Version 40.72 (Not verified) NVIDIA Corporationd:\windows\system32\nvshell.dll

+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 40.72 (Not verified) NVIDIA Corporationd:\windows\system32\nvshell.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell Extensions(Not verified) RealNetworks, Inc.d:\program files\real\realone player\rpshell.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web 文件夹d:\program files\common files\microsoft shared\web folders\msonsext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch Module(Not verified) Amaze Softd:\program files\flashget\jccatch.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ FlashGetFlashGet(Not verified) Amaze Softd:\program files\flashget\flashget.exe

BlackStone - 2005-11-15 8:54:00
【回复“阿蛮”的帖子】
日志里看不出有啥问题
你的机子有啥异常嘛
流浪射手 - 2005-11-16 12:09:00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ nwizNVIDIA nView Wizard, Version 100.43 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe

+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.c:\windows\soundman.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

HKLM\System\CurrentControlSet\Services

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ NVMLCFile not found: C:\WINDOWS\System32\ronvidiat.dll

+ WinMediaRoNVidiaRoNVidiac:\windows\system32\nvbworks.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe

+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

BlackStone - 2005-11-16 12:29:00
【回复“流浪射手”的帖子】
+ WinMediaRoNVidiaRoNVidiac:\windows\system32\nvbworks.dll

禁用重启试试
七彩黄花菜萱草 - 2005-11-16 22:29:00
13楼是不是有点出入啊?
这句"此工具可以替换window资源管理器,选择Options-Replace Task Manager,则每次启动任务管理器时则启动此程序"红线部份是否应为"任务管理器".
12345678
查看完整版本: 【原创】如何用Procexp和Autoruns工具识别与删除木马程序