瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】求救:中了Worm.Win32.Agent.xt杀不掉

12   2  /  2  页   跳转

【原创】求救:中了Worm.Win32.Agent.xt杀不掉

正在运行的进程
[PID: 588 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 656 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 680 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\klogon.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\417D91A6.DLL]  [Microsoft Corporation, ]
[PID: 724 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 736 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 884 / SYSTEM][C:\WINDOWS\System32\ibmpmsvc.exe]  [N/A, ]
[PID: 940 / SYSTEM][C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe]  [N/A, ]
    [C:\Program Files\ThinkPad\Utilities\TpKmapHk.dll]  [N/A, ]
[PID: 948 / SYSTEM][C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe]  [N/A, ]
    [C:\Program Files\ThinkPad\Utilities\TpKmapHk.dll]  [N/A, ]
[PID: 964 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1100 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1332 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1412 / LOCAL SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1592 / leon][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\System32\417D91A6.DLL]  [Microsoft Corporation, ]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\System32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.7]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\k5379374994.DAT]  [N/A, ]
    [C:\WINDOWS\System32\dh2104.dll]  [N/A, ]
    [C:\WINDOWS\System32\MOSOU.dll]  [N/A, ]
    [C:\WINDOWS\System32\XPSP2RES.DLL]  [Microsoft Corporation, 5.1.2600.1125 (xpsp2.020921-0842)]
    [C:\WINDOWS\System32\WinForm.dll]  [N/A, ]
    [C:\WINDOWS\System32\nwizqjsj.dll]  [N/A, ]
    [C:\WINDOWS\System32\TIMHost.dll]  [N/A, ]
    [C:\WINDOWS\System32\nwizwlwzs.dll]  [N/A, ]
    [C:\Program Files\FlashGet\fgmgr.dll]  [www.flashget.com, 1, 8, 4, 1007]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
gototop
 

[C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\ShellEx.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
[PID: 1764 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1888 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [C:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\WINDOWS\System32\417D91A6.DLL]  [Microsoft Corporation, ]
[PID: 260 / SYSTEM][C:\WINDOWS\System32\Ati2evxx.exe]  [, ]
[PID: 996 / SYSTEM][C:\WINDOWS\System32\QCONSVC.EXE]  [N/A, ]
[PID: 1304 / leon][C:\WINDOWS\System32\tp4serv.exe]  [IBM Corporation, 3.09]
    [C:\WINDOWS\System32\tp4uires.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1408 / leon][C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe]  [N/A, ]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\ThinkPad\PkgMgr\HOTKEY_2\tphk_2k.dll]  [N/A, ]
    [C:\WINDOWS\System32\Oemdspif.dll]  [ATI Technologies, Inc., 4.12.0007]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1512 / leon][C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1524 / leon][C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe]  [N/A, ]
    [C:\Program Files\ThinkPad\Utilities\TpKmapHk.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1544 / leon][C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe]  [IBM Corporation, 1.06]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1848 / leon][C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE]  [N/A, ]
    [C:\Program Files\ThinkPad\ConnectUtilities\QCON.dll]  [N/A, ]
    [C:\Program Files\ThinkPad\ConnectUtilities\MerlinC201.dll]  [Novatel Wireless Inc., 1, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1108 / leon][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1536 / leon][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe]  [IBM Corp., 1, 0, 0, 0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1964 / leon][C:\WINDOWS\AGRSMMSG.exe]  [Agere Systems, 2.1.21 2.1.21 11/21/2002 14:17:53]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2072 / leon][C:\Program Files\Support.com\bin\tgcmd.exe]  [SupportSoft, Inc., 5,8,136,0]
    [C:\Program Files\Support.com\bin\2052\tglocale.dll]  [, ]
    [C:\Program Files\Support.com\bin\sdcmon.dll]  [SupportSoft, Inc., 5,8,136,0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [C:\WINDOWS\System32\k5379374994.DAT]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Support.com\bin\tgctlsi.dll]  [SupportSoft, Inc., 5,8,136,0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.2.621]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.2.621]
[PID: 2128 / leon][C:\Program Files\IBM\Messages By IBM\ibmmessages.exe]  [IBM, 1.058]
    [C:\WINDOWS\System32\AIBMRUNL.dll]  [N/A, ]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2320 / leon][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.1622]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2504 / leon][C:\WINDOWS\System32\ntsd.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 2548 / leon][C:\WINDOWS\System32\ntsd.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 2616 / leon][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2748 / leon][C:\WINDOWS\System32\ntsd.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 3092 / leon][C:\WINDOWS\System32\wuauclt.exe]  [Microsoft Corporation, 5.4.3630.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\k5379374994.DAT]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3112 / leon][C:\WINDOWS\System32\ntsd.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 3348 / leon][C:\WINDOWS\System32\ntsd.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 3256 / leon][C:\Program Files\FlashGet\flashget.exe]  [FlashGet.com, 1, 9, 0, 1012]
    [C:\Program Files\FlashGet\FGBTCORE.dll]  [, 1, 0, 0, 36]
    [C:\Program Files\FlashGet\FGEMCORE.dll]  [, 1, 0, 3, 1002]
    [C:\Program Files\FlashGet\debugrpt.dll]  [flashget, 1, 0, 0, 1006]
    [C:\WINDOWS\System32\MOSOU.dll]  [N/A, ]
    [C:\WINDOWS\System32\k5379374994.DAT]  [N/A, ]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\WinForm.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\FlashGet\fgmgr.dll]  [www.flashget.com, 1, 8, 4, 1007]
    [C:\Program Files\FlashGet\fgupdate.dll]  [www.flashget.com, 1, 8, 1, 1003]
    [C:\Program Files\FlashGet\dbghelp.dll]  [Microsoft Corporation, 6.6.0007.5 (debuggers(dbg).051021-1446)]
[PID: 3360 / leon][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\Program Files\FlashGet\fgmgr.dll]  [www.flashget.com, 1, 8, 4, 1007]
    [C:\WINDOWS\System32\MOSOU.dll]  [N/A, ]
    [C:\WINDOWS\System32\k5379374994.DAT]  [N/A, ]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\FlashGet\jccatch.dll]  [www.flashget.com, 1, 8, 4, 1007]
    [C:\Program Files\FlashGet\getflash.dll]  [www.flashget.com, 1, 8, 4, 1003]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\WinForm.dll]  [N/A, ]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\System32\TIMHost.dll]  [N/A, ]
[PID: 4024 / leon][C:\WINDOWS\system32\NOTEPAD.EXE]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\FlashGet\fgmgr.dll]  [www.flashget.com, 1, 8, 4, 1007]
    [C:\WINDOWS\System32\MOSOU.dll]  [N/A, ]
    [C:\WINDOWS\System32\k5379374994.DAT]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\TIMHost.dll]  [N/A, ]
    [C:\WINDOWS\System32\WinForm.dll]  [N/A, ]
[PID: 3920 / leon][D:\Downloads\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\Program Files\FlashGet\fgmgr.dll]  [www.flashget.com, 1, 8, 4, 1007]
    [C:\WINDOWS\System32\MOSOU.dll]  [N/A, ]
    [C:\WINDOWS\System32\k5379374994.DAT]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\System32\TIMHost.dll]  [N/A, ]
    [C:\WINDOWS\System32\WinForm.dll]  [N/A, ]
    [D:\Downloads\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[C:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[D:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 940, C:\PROGRAM FILES\THINKPAD\UTILITIES\TPKMAPMN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 948, C:\PROGRAM FILES\THINKPAD\UTILITIES\TPKMAPMN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1408, C:\PROGRA~1\THINKPAD\PKGMGR\HOTKEY\TPHKMGR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1512, C:\PROGRAM FILES\THINKPAD\PKGMGR\HOTKEY\TPONSCR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1524, C:\PROGRAM FILES\THINKPAD\UTILITIES\TPKMAPMN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1544, C:\PROGRAM FILES\THINKPAD\PKGMGR\HOTKEY_1\TPSCREX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1848, C:\PROGRAM FILES\THINKPAD\CONNECTUTILITIES\QCWLICON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1536, C:\PROGRA~1\THINKPAD\UTILIT~1\EZEJMNAP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2072, C:\PROGRAM FILES\SUPPORT.COM\BIN\TGCMD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2128, C:\PROGRAM FILES\IBM\MESSAGES BY IBM\IBMMESSAGES.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2320, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3256, C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3256, C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE]

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\System32\TIMHost.dll)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\System32\TIMHost.dll)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\System32\drivers\klif.sys)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

以上是全部啊 大家帮帮忙
gototop
 

删除以下启动项
<Microsoft Autorun5><C:\WINDOWS\System32\mosou.exe> []
<Microsoft Autorun7><C:\WINDOWS\System32\nwizqjsj.exe> []
<Microsoft Autorun11><C:\WINDOWS\System32\nwizwlwzs.exe> []
<WinForm><C:\WINDOWS\WinForm.exe> []
<TIMHost><C:\WINDOWS\TIMHost.exe> []
<Microsoft Autorun1><C:\WINDOWS\System32\nwizdh.exe> []
<N/A><C:\WINDOWS\System32\nwizzhuxians.exe> []
删除以下服务
[4E4B2F24 / 4E4B2F24][Stopped/Auto Start]
<C:\WINDOWS\System32\C67FC274.EXE -k><Microsoft Corporation>
删除进程中调用的以下文件
[C:\WINDOWS\System32\k5379374994.DAT] [N/A, ]
[C:\WINDOWS\System32\dh2104.dll] [N/A, ]
[C:\WINDOWS\System32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\System32\WinForm.dll] [N/A, ]
[C:\WINDOWS\System32\nwizqjsj.dll] [N/A, ]
[C:\WINDOWS\System32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\System32\nwizwlwzs.dll] [N/A,
删除C D盘下的autorun.inf
并将上述有问题的启动项 服务原文件删除
gototop
 

谢谢了 但是一些找不到 删了一些这个删不掉C:\WINDOWS\System32\MOSOU.dll] [N/A, ]
gototop
 

应该是被进程调用了,用Icesword从进程中把这个强行卸载了。再删就行了
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT