瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 在system32里有个rundll.exe和一个msheart.exe是木马怎么干掉啊

12   1  /  2  页   跳转

在system32里有个rundll.exe和一个msheart.exe是木马怎么干掉啊

在system32里有个rundll.exe和一个msheart.exe是木马怎么干掉啊

我用杀毒软件和木马克星根本干不掉。。连重装系统都没办法。启动盘放进去,重启,他不跳出格式化硬盘的页面。。哪位大大帮帮忙啊。。急啊
最后编辑2006-05-26 22:55:34
分享到:
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=6979213第5楼下载System Repair Engineer 2.0.12.350导出全部日志。
gototop
 

2006-05-26,22:11:38

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Home Edition  - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <KpopMon><C:\KAV6\KPopMon.EXE>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KAVRun><C:\KAV6\KAVRun.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <Kulansyn><C:\KAV6\Kulansyn.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <iDuba Personal FireWall><rem C:\KAV6\KAVPFW.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <nwiz><rem nwiz.exe /install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SoundMan><SOUNDMAN.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><rem "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <iparmor><C:\Program Files\Iparmor\Iparmor.exe mini>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
服务
[IMAPI CD-Burning COM Service / ImapiService]
  <C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[Kingsoft AntiVirus Service / KAVSvc]
  <C:\KAV6\KAVSvc.EXE><kingsoft Antivirus>
[LexBce Server / LexBceS]
  <C:\WINDOWS\system32\LEXBCES.EXE><Lexmark International, Inc.>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\System32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll, N/A>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, N/A>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, N/A>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL, N/A>
[MMSAssist BHO]
  {6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <E:\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[MMSAssistMenu]
  {6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[金山卓越]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <url:http://www.joyo.com, N/A>
[易趣购物]
  {DE607141-AC19-421e-869A-9D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[金山毒霸网站]
  {e1fc9760-7b95-49cd-80b9-8c9e41017b93} <url:http://www.duba.net, N/A>
[在线查毒]
  {f58d36c3-40be-4418-a786-d8fbe3eb3554} <C:\KAV6\kavie.htm, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[BitCometBar]
  {3F1ABCDB-A875-46c1-8345-B72A4567E486} <C:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll, N/A>
[金山毒霸]
  {A9BE2902-C447-420A-BB7F-A5DE921E6138} <C:\KAV6\KAIEPlus.DLL, >
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, N/A>
[XML DOM Document 4.0]
  {88D969C0-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml4.dll, N/A>
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[  >> 彩信发送 <<]
  <res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <F:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
  <E:\KuGoo3\KuGoo3DownX.htm, N/A>
[添加到QQ自定义面板]
  <F:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <F:\QQ\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
  <F:\QQ\SendMMS.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll/246, N/A>

gototop
 

==================================
正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 588][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 612][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 656][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 668][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 840][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 940][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1032][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1052][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1204][C:\WINDOWS\system32\LEXBCES.EXE]  <Lexmark International, Inc.><7.1>
    [C:\WINDOWS\system32\lexp2p32.dll]  <Lexmark International, Inc.><7.1>
    [C:\WINDOWS\system32\lex2kusb.dll]  <Lexmark International, Inc.><7.1>
[PID: 1244][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
    [C:\WINDOWS\system32\LEXLMPM.DLL]  <Lexmark International, Inc.><7.1>
    [C:\WINDOWS\system32\LexBce.dll]  <Lexmark International, Inc.><7.1>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\LGAIPP5C.dll]  <Lexmark International><0.1.41.0>
    [C:\WINDOWS\system32\lgaipwr.dll]  <Lexmark International, Inc.><0, 1, 33, 1>
[PID: 1252][C:\WINDOWS\system32\LEXPPS.EXE]  <Lexmark International, Inc.><7.1>
    [C:\WINDOWS\system32\LEXBCE.DLL]  <Lexmark International, Inc.><7.1>
[PID: 1596][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\WINDOWS\System32\NVCPL.DLL]  <NVIDIA Corporation><6.14.10.5655>
    [C:\WINDOWS\System32\nvshell.dll]  <NVIDIA Corporation><6.14.10.5655>
    [C:\WINDOWS\System32\NVWRSZHC.DLL]  <NVIDIA Corporation><6.14.10.5655>
    [C:\WINDOWS\System32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\KAV6\KAVEXT.DLL]  <Kingsoft Corp.><2002, 5, 24, 6>
[PID: 1744][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.00>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1764][C:\KAV6\KWatchUI.EXE]  <><2004.1.6.119>
    [C:\KAV6\kavcomm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\kavdlg.dll]  <><2004.7.20.81>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1780][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1788][C:\KAV6\KPopMon.EXE]  <><2004, 2, 2, 31>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1844][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1872][C:\KAV6\KAVSvc.EXE]  <kingsoft Antivirus><2003, 11, 12, 70>
    [C:\KAV6\SvcComm.dll]  <kingsoft Antivirus><2004, 7, 28, 1>
    [C:\KAV6\SvcTimer.DLL]  <Kingsoft><2004.4.29.79>
    [C:\KAV6\KavComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KWatchFn2.dll]  <kingsoft Corporation><2004, 8, 24, 25>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2004, 11, 26, 53>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2004, 11, 9, 11>
    [C:\KAV6\KAVUtils.dll]  <Kingsoft Corp><2004, 2, 12, 69>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
[PID: 1936][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.5655>
[PID: 1964][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 384][C:\KAV6\MailMon.EXE]  <Kingsoft Co., Ltd><2004, 2, 6, 245>
    [C:\KAV6\KMFilter.DLL]  <><2004, 3, 1, 37>
    [C:\KAV6\parse822.dll]  <Quiksoft Corporation><2, 0, 0, 9>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\KAMsgBox.DLL]  <><2002.9.27.30>
    [C:\KAV6\KAVComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KAVIPC.DLL]  <Kingsoft Corp.><2002, 3, 29, 8>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAECall.DLL]  <Kingsoft Corporation><2003, 11, 14, 66>
    [C:\KAV6\KAEScan.DLL]  <Kingsoft Corp.><2003, 5, 24, 36>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2004, 11, 26, 53>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2004, 11, 9, 11>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 960][C:\KAV6\KAVPlus.EXE]  <><2004, 3, 3, 71>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 284][C:\WINDOWS\System32\wuauclt.exe]  <Microsoft Corporation><5.4.2600.0 (XPClient.010817-1148)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1932][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\WINDOWS\System32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
    [C:\PROGRA~1\MMSASS~1\Mmsass~1.dll]  <><1, 2, 0, 2>
    [E:\KuGoo3\KuGoo3DownXControl.ocx]  <N/A><N/A>
    [C:\KAV6\KAVEXT.DLL]  <Kingsoft Corp.><2002, 5, 24, 6>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\WINDOWS\Downloaded Program Files\OL2005.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 3276][C:\Documents and Settings\admin\桌面\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>

==================================
文件关联
.TXT  Error. [Notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

哪位大大看一下??
gototop
 

并没有发现你所说的那两个文件在运行啊。
另外,楼主在用SREng的时候是否修改了什么,记得木马克星应该有一个DLL文件在
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
这个位置的,运行SREng时会提醒你AppInit_DLLs的值非空的,楼主是否在那个时候修改了?
gototop
 

我装好木马克星就没去动过。。后来我看没什么效果就把他删了。。
gototop
 

是空的。。但是SREng没有提醒我什么。。
gototop
 

那两个文件现在还出现吗?还是每次重启之后就再出现?
gototop
 

删了之后刷新一下就出现
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT