瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 帮我看看日志吧(无限感激)mopery麻烦再进来看下

12345   2  /  5  页   跳转

帮我看看日志吧(无限感激)mopery麻烦再进来看下

C:\WINDOWS\system32\ooo.exe
C:\WINDOWS\system32\iexplore.exe
这2个文件找了1个小时也找不到,是不是被隐藏了,还是怎么了.system32有9个是隐藏文件,是不是被隐藏了,还是怎么了.告诉我下怎么才能找到,
其它你要求的操作我都做可.
还有我这样不是一次,按照你要求完成,对杀毒有没有影响.
实在不好意思多次麻烦你.实在是电脑不能玩,急啊,请见谅~~
gototop
 

可以用winrar 这个压缩 工具
或者
开始-运行-cmd
输入
attrib -s -h /s /d C:\WINDOWS\system32\ooo.exe
attrib -s -h /s /d C:\WINDOWS\system32\iexplore.exe
然后再看看是否有这俩个文件..
gototop
 

2个方法都用了,还是找不到这2个文件.
我按你要求的操作后,(除了那2个找不到的文件).重起后用瑞星杀了下,有发现了好多新病毒,Adware,RootKit,Trojan.dL.等不知道怎么回事
gototop
 

C:\WINDOWS\system32\vicsc.dll] [N/A, ]
C:\Program Files\WinRAR\rarext.dll] [N/A, ]
这两个也要删除!
gototop
 

C:\WINDOWS\system32\ooo.exe
C:\WINDOWS\system32\iexplore.exe
那这2个找不到的文件怎么办啊
gototop
 

找不到就算了。

再扫个新日志看看。

你原日志中的正在运行的进程里看到这个:

C:\WINDOWS\system32\F0D78D11.DLL

插了重要进程里,估计难处理了。

你用WinRAR打开各个磁盘,看根目录下是否有不明文件,有不明的,发大图来瞧瞧。
gototop
 

引用:
【独守寒江的贴子】我按照你的操作,在正常模式下[B302EC43 / B302EC43][Stopped/Auto Start]
<C:\WINDOWS\system32\75D23BE4.EXE -d><Microsoft Corporation>
删除不掉啊,一删除就被取消了
………………

有没看清楚提示,在弹出的窗口中点否,不是点是。。!
gototop
 

【回复“独守寒江”的帖子】
我按照你的操作,在正常模式下[B302EC43 / B302EC43][Stopped/Auto Start]
<C:\WINDOWS\system32\75D23BE4.EXE -d><Microsoft Corporation>
删除不掉啊,一删除就被取消了




你有没看清楚提示。。。在弹出的窗口中点否,不是点是。

<SREng-启动项目->服务->驱动程序"选中"隐藏已认证的微软服务" 删除
[oiqt / oiqtd][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\oiqtd.sys><N/A>


然后删除C:\WINDOWS\system32\DRIVERS\oiqtd.sys
gototop
 

我一打开Sreng就提示发现2个隐藏进程,还有下面的函数内容与预期制不符,他们可能被一些恶意软件所修改,入口点错误:FreeLibrary
这是我新扫的日志
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><; nwiz.exe /install>  []
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [N/A]
    <SoundMan><; SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <ads1><C:\Program Files\Internet Explorer\nvsvc.exe genxing>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KASTask><F:\Kingsoft Antispy\KASTask.EXE>  [(Verified)KINGSOFT CORPORATION]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\BLISS.SCR>  [Microsoft]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[HostService / HostService][Running/Auto Start]
  <C:\Program Files\Internet Explorer\nvsvc.exe><N/A>


gototop
 

我一打开Sreng就提示发现2个隐藏进程,还有下面的函数内容与预期制不符,他们可能被一些恶意软件所修改,入口点错误:FreeLibrary
这是我新扫的日志
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><; nwiz.exe /install>  []
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [N/A]
    <SoundMan><; SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <ads1><C:\Program Files\Internet Explorer\nvsvc.exe genxing>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KASTask><F:\Kingsoft Antispy\KASTask.EXE>  [(Verified)KINGSOFT CORPORATION]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\BLISS.SCR>  [Microsoft]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[HostService / HostService][Running/Auto Start]
  <C:\Program Files\Internet Explorer\nvsvc.exe><N/A>
gototop
 
12345   2  /  5  页   跳转
页面顶部
Powered by Discuz!NT