删删删不掉 - 2007-5-3 1:09:00
瑞星监控不断提示:Trojan.PSW.Agent.jvs
Trojan.PSW.WorldOnline.ey
Trojan.PSW.OnlineGames.ath
Trojan.PSW.OnlineGames.axn
Trojan.PSW.OnlineGames.aye
可总是杀不了,重启又有,伤透脑筋啦~~~~~~~~~~~~~~~~
[CODE]
2005-05-03,00:37:25
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Windows XP Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows XP Publisher]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows XP Publisher]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows XP Publisher]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /install> []
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SKYNET Personal FireWall><F:\天网\FIREWALL\pfw.exe> [N/A]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<RavTask><"F:\瑞星杀毒\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<upxdnd><C:\DOCUME~1\tt\LOCALS~1\Temp\upxdnd.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<winform><C:\WINDOWS\winform.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<ronney><C:\WINDOWS\ronney.exe /i> []
<!AVG Anti-Spyware><"F:\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows XP Publisher]
<Userinit><C:\WINDOWS\System32\userinit.exe,> [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows XP Publisher]
==================================
启动文件夹
[快捷方式 到 avgas]
<C:\Documents and Settings\tt\「开始」菜单\程序\启动\快捷方式 到 avgas.lnk --> F:\AVGANT~1.5\avgas.exe [Anti-Malware Development a.s.]><N>
==================================
服务
[41D01BE6 / 41D01BE6][Stopped/Auto Start]
<C:\WINDOWS\System32\41D01BE6.EXE -k><Microsoft Corporation>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
<F:\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"F:\瑞星杀毒\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"F:\瑞星杀毒\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\F:\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[BaseTDI / BaseTDI][Running/Auto Start]
<\??\C:\WINDOWS\System32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\F:\瑞星杀毒\RISING\RAV\ExpScan.sys><>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
<System32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HookCont / HookCont][Running/Auto Start]
<\??\F:\瑞星杀毒\RISING\RAV\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\F:\瑞星杀毒\RISING\RAV\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\F:\瑞星杀毒\RISING\RAV\HookSys.sys><Rising>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\F:\瑞星杀毒\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
[nv / nv][Running/Manual Start]
<System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\F:\瑞星杀毒\RISING\RAV\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><N/A>
==================================
浏览器加载项
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Tencent Safety Online Base Module]
{C09B522F-8AED-4E21-A65C-DC1AB652BAEE} <C:\WINDOWS\DOWNLO~1\TSOBase.ocx, Tencent Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
<E:\2005QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<E:\2005QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\2005QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\2005QQ\SendMMS.htm, N/A>
删删删不掉 - 2007-5-3 1:11:00
正在运行的进程
[PID: 552][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 640][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 664][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 708][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 720][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 904][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 1420][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\DOCUME~1\tt\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\System32\mppds.dll] [N/A, ]
[C:\WINDOWS\System32\winform.dll] [N/A, ]
[C:\WINDOWS\System32\msccrt.dll] [N/A, ]
[C:\WINDOWS\System32\ronney.dll] [N/A, ]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[F:\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[F:\瑞星杀毒\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1652][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 1744][C:\WINDOWS\ronney.exe] [N/A, ]
[C:\WINDOWS\System32\ronney.dll] [N/A, ]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 236][F:\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[F:\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 296][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[PID: 3620][C:\Documents and Settings\tt\桌面\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\System32\msccrt.dll] [N/A, ]
[C:\WINDOWS\System32\mppds.dll] [N/A, ]
[C:\WINDOWS\System32\winform.dll] [N/A, ]
[C:\WINDOWS\System32\ronney.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[D:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[E:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
删删删不掉 - 2007-5-3 1:15:00
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 008.cn
127.0.0.1 ultimate-best-hgh.0my.net
127.0.0.1 www.139500.com
127.0.0.1 www.1yin.net
127.0.0.1 ****cn
127.0.0.1 www.37021.com
127.0.0.1 www.47555.net
127.0.0.1 www.511ring.com
127.0.0.1 me.5e163.com
127.0.0.1 www.777888.com
127.0.0.1 www.77ttt.com
127.0.0.1 www.9p.cn
127.0.0.1 abcdesign.ru
127.0.0.1 gutemine.wu-wien.ac.at
127.0.0.1 math.kobe-u.ac.jp
127.0.0.1 www.aifind.info
127.0.0.1 www.allyes.com
127.0.0.1 www.aogo.net
127.0.0.1 baltnet.ru
127.0.0.1 quotes.barchart.com
127.0.0.1 free.bestialityhost.com
127.0.0.1 cctv1.net
127.0.0.1 cctv8.net
127.0.0.1 www.cctv8.net
127.0.0.1 ciachoo.pl
127.0.0.1 www.play.cn.gs
127.0.0.1 www.cnqb.net
127.0.0.1 www.feixue.net
127.0.0.1 www.xiliao.com.cn
127.0.0.1 alexey.pioneers.com.ru
127.0.0.1 www.coolcdrom.com
127.0.0.1 www.coolseach.com
127.0.0.1 puldk490gj.da.ru
127.0.0.1 dicto.ru
127.0.0.1 www.dj3344.com
127.0.0.1 www.donttrip.org
127.0.0.1 www.ehomeday.com
127.0.0.1 elemental.ru
127.0.0.1 errorguard.com
127.0.0.1 friendlygreeting.com
127.0.0.1 zhp.gdynia.pl
127.0.0.1 www.gg888.net
127.0.0.1 gin.ru
127.0.0.1 www.girlchinese.com
127.0.0.1 glass-master.ru
127.0.0.1 photo.gornet.ru
127.0.0.1 relay.great.ru
127.0.0.1 hack-gegen-rechts.com
127.0.0.1 hgrstrailer.com
127.0.0.1 www.homepage.com
127.0.0.1 hotbar.com
127.0.0.1 intellect.lvc
127.0.0.1 interfoodtd.ru
127.0.0.1 jewishgen.org
127.0.0.1 www.jixian.net
127.0.0.1 k2kapital.com
127.0.0.1 security.kolla.de
127.0.0.1 www.kuliao.com
127.0.0.1 laugh-mail.net
127.0.0.1 7b.com.cn
127.0.0.1 9505.com
127.0.0.1 www.piaoxue.com
127.0.0.1 marketscore.com
127.0.0.1 www.mir0.com
127.0.0.1 momentum.ru
127.0.0.1 www.mtv51.com
127.0.0.1 www.mydj2005.com
127.0.0.1 nefkom.net
127.0.0.1 no-abi2003.de
127.0.0.1 tdi-router.opola.pl
127.0.0.1 packages.debian.or.jp
127.0.0.1 perfectgirls.net
127.0.0.1 peterstar.ru
127.0.0.1 pgipearls.com
127.0.0.1 phg.pl
127.0.0.1 vip.pnet.pl
127.0.0.1 sec.polbox.pl
127.0.0.1 polobeer.de
127.0.0.1 porno-mania.net
127.0.0.1 home.profootball.ru
127.0.0.1 qianbai.com
127.0.0.1 ad.qingyule.com
127.0.0.1 www.qq168.net
127.0.0.1 www.qq3344.com
127.0.0.1 www.qq92.com
127.0.0.1 www.qqwz.com
127.0.0.1 www.qu123.com
127.0.0.1 republika.pl
127.0.0.1 www.richfind.com
127.0.0.1 rollenspielzirkel.de
127.0.0.1 safer-networking.org
127.0.0.1 sdsauto.ru
127.0.0.1 www.searchpage.cc
127.0.0.1 www.seekeasysoft.net
127.0.0.1 shadkhan.ru
127.0.0.1 slavarik.ru
127.0.0.1 sovea.de
127.0.0.1 spybot.info
127.0.0.1 www.start-page.info
127.0.0.1 lars-s.privat.t-online.de
127.0.0.1 u.t2cn.com
127.0.0.1 www.7939.com
127.0.0.1 www.4199.com
127.0.0.1 www.3448.com
127.0.0.1 www.6781.com
127.0.0.1 it.trendmicro-europe.com
127.0.0.1 trendmicro.it
127.0.0.1 truefriends.net
127.0.0.1 www.tthao.com
127.0.0.1 www.ttrx.net
127.0.0.1 tuhart.net
127.0.0.1 www.unionsky.cn
127.0.0.1 www.unionsky.com
127.0.0.1 www.unionsky.net
127.0.0.1 vconsole.net
127.0.0.1 virtumonde.com
127.0.0.1 gamma.vyborg.ru
127.0.0.1 financial.washingtonpost.com
127.0.0.1 webpark.pl
127.0.0.1 wishken.com
127.0.0.1 www.yeapple.com
127.0.0.1 www.yibinren.com
127.0.0.1 www.youmiss.com
127.0.0.1 www.yysky.net
127.0.0.1 zelnet.ru
127.0.0.1 www.zhengdian.com
127.0.0.1 abc.265.com
127.0.0.1 555.265.com
127.0.0.1 www.baidu345.com
127.0.0.1 www.37ss.com
127.0.0.1 my123.com
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
tk26 - 2007-5-3 1:23:00
<upxdnd><C:\DOCUME~1\tt\LOCALS~1\Temp\upxdnd.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<winform><C:\WINDOWS\winform.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<ronney><C:\WINDOWS\ronney.exe /i> []
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
[C:\DOCUME~1\tt\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\System32\mppds.dll] [N/A, ]
[C:\WINDOWS\System32\winform.dll] [N/A, ]
[C:\WINDOWS\System32\msccrt.dll] [N/A, ]
[C:\WINDOWS\System32\ronney.dll] [N/A, ]
[C:\WINDOWS\System32\41D01BE6.DLL] [Microsoft Corporation, ]
tk26 - 2007-5-3 1:42:00
C:\DOCUME~1\tt\LOCALS~1\Temp\upxdnd.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\winform.exe C:\WINDOWS\msccrt.exe
C:\WINDOWS\ronney.exe
C:\WINDOWS\System32\41D01BE6.DLL
C:\DOCUME~1\tt\LOCALS~1\Temp\upxdnd.dll
C:\WINDOWS\System32\mppds.dll
C:\WINDOWS\System32\winform.dll
C:\WINDOWS\System32\msccrt.dll
C:\WINDOWS\System32\ronney.dll
C:\WINDOWS\System32\41D01BE6.DLL
显示隐藏文件(我的电脑-工具-文件夹选项-查看-显示受保护的操作系统文件) 删除上面的文件
删了这些启动项
<upxdnd>
<mppds>
<winform>
<msccrt>
<ronney>
© 2000 - 2026 Rising Corp. Ltd.