瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 删除了病毒,机子运行更慢了!!!还发现 Win32/Malum.EUC,是个什么DD!

123   3  /  3  页   跳转

删除了病毒,机子运行更慢了!!!还发现 Win32/Malum.EUC,是个什么DD!

正在运行的进程
[PID: 644][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 708][\??\D:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 836][\??\D:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 880][D:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 892][D:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1048][D:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1108][D:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
[PID: 1200][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
[PID: 1324][D:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1396][D:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
[PID: 1624][D:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
    [e:\tool\test\WinRAR\rarext.dll]  <N/A><N/A>
    [D:\WINDOWS\avshlext.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><6.0.1.2003110300>
    [D:\PROGRA~1\baidu\bar\baidubar.dll]  <Baidu.com, Inc.><2, 0, 2, 62>
    [D:\WINDOWS\system32\xunleibho_v8.dll]  <Thunder Networking Technologies,LTD><4, 5, 1, 33>
    [D:\WINDOWS\system32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.8194>
    [D:\WINDOWS\system32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.8194>
    [D:\WINDOWS\system32\nvshell.dll]  <N/A><N/A>
    [D:\WINDOWS\system32\CmdLineExt03.dll]  <N/A><N/A>
[PID: 1692][D:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1924][D:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5, 1, 0, 50>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
[PID: 1940][E:\TOOL\eTrust EZ Antivirus\CAVTray.exe]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\CAVScan.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\DriverIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\CAVFrm.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\iSafProd.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\EZAVLic.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\CAVProd.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\CAVres.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
[PID: 1952][E:\TOOL\eTrust EZ Antivirus\CAVRID.exe]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\CAVFrm.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\CAVProd.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\CAVres.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
[PID: 1972][E:\TOOL\SKYNET\FIREWALL\pfw.exe]  <广州众达天网技术有限公司><2.7.6.1005>
gototop
 

[E:\TOOL\SKYNET\FIREWALL\SKYMISC.DLL]  <N/A><N/A>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
[PID: 1980][D:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
[PID: 2016][D:\Program Files\Logitech\MouseWare\system\em_exec.exe]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Logitech\MouseWare\system\EVENTEX.dll]  <Logitech Inc.><9.80.019>
    [D:\WINDOWS\system32\COMNCTR.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Logitech\MouseWare\system\ccresrce.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Logitech\MouseWare\system\GlbResLt.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [D:\Program Files\Logitech\MouseWare\System\devices.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Logitech\MouseWare\system\ccstmglb.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Logitech\MouseWare\system\ccustom.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Logitech\MouseWare\system\ccmsghk.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
[PID: 236][E:\TOOL\eTrust EZ Antivirus\ISafe.exe]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\iSafProd.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\Arclib.dll]  <Computer Associates International, Inc.><7.2.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\ISafeEngine.dll]  <Computer Associates International, Inc.><Version 12.4.1.0>
[PID: 248][D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  <Microsoft Corporation><7.00.9466>
[PID: 308][D:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.8194>
[PID: 496][E:\TOOL\eTrust EZ Antivirus\VetMsg.exe]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\DriverIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [E:\TOOL\eTrust EZ Antivirus\VetNtMsg.dll]  <N/A><N/A>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\iSafProd.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
[PID: 1572][D:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
[PID: 2196][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1860][D:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
    [D:\PROGRA~1\baidu\bar\baidubar.dll]  <Baidu.com, Inc.><2, 0, 2, 62>
    [D:\WINDOWS\system32\xunleibho_v8.dll]  <Thunder Networking Technologies,LTD><4, 5, 1, 33>
    [E:\TOOL\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><6.0.1.2003110300>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [D:\WINDOWS\system32\CHENHU4.IME]  <chenhu><5.7>
    [D:\PROGRA~1\baidu\bar\BDBar_tmp\BaiduBar.dll]  <Baidu.com, Inc.><2, 0, 2, 78>
    [D:\PROGRA~1\baidu\bar\bdgdins.dll]  <Baidu.com, Inc.><1, 1, 5, 0>
    [D:\WINDOWS\system32\macromed\flash\flash.ocx]  <Macromedia, Inc.><6,0,79,0>
[PID: 2164][D:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
[PID: 3716][D:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
    [D:\PROGRA~1\baidu\bar\baidubar.dll]  <Baidu.com, Inc.><2, 0, 2, 62>
    [D:\WINDOWS\system32\xunleibho_v8.dll]  <Thunder Networking Technologies,LTD><4, 5, 1, 33>
    [E:\TOOL\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><6.0.1.2003110300>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [D:\WINDOWS\system32\VetRedir.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\ISafeIf.dll]  <Computer Associates International, Inc.><Version 11.0.1.4>
    [D:\WINDOWS\system32\macromed\flash\flash.ocx]  <Macromedia, Inc.><6,0,79,0>
[PID: 1248][G:\shadu\sreng2\streng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [D:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.80.019>
    [D:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["D:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
CA ISafe LSP over [MSAFD Tcpip [TCP/IP]]
    D:\WINDOWS\system32\VetRedir.dll(Computer Associates International, Inc., ISafe LSP)
CA ISafe LSP
    D:\WINDOWS\system32\VetRedir.dll(Computer Associates International, Inc., ISafe LSP)

==================================
gototop
 

实在受不了了,内存被占光了,把系统盘格了,昨天奋战到2点多~~~再贴个日志看看,不知还有没有残余。。。。
gototop
 

这日志看不出问题了。
gototop
 

呵呵,搞了几天,总算可以安下心了哦。。。。
gototop
 

楼主的日志看不出问题,你说现在可以安心了,是否以经找到的解决的方法,还望写上来。
gototop
 

什么意思啊  看不懂
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT