瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 帮我看看rojan.PSW这个病毒杀不掉,附日志

1   1  /  1  页   跳转

帮我看看rojan.PSW这个病毒杀不掉,附日志

帮我看看rojan.PSW这个病毒杀不掉,附日志

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe>  []
    <YOKAssiant><Rundll32.exe C:\PROGRA~1\YOK.com\SuperSearch\YOK_SuperSearch.dll,YOKAssiant>  [www.YOK.com]
    <TkBellExe><"C:\Program Files\Kuree\codec\realsched.exe"  -osboot>  []
    <Thunder><"C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s>  [Thunder Networking Technologies,LTD]
    <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><EXPLORER.EXE>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><KB3999522.LOG>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll>  [北京三七二一科技有限公司]
    <{08315C1A-9BA9-4B7C-A432-26885F9QQDSQ}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\qqdsq2.lmz>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <SysTime><C:\PROGRA~1\WinKld\WinKld.dll>  []
    <themeadp><C:\WINDOWS\system32\themeadp.dll>  []
    <webwork><C:\WINDOWS\webwork\webwork.dll>  []
    <MediaCheck><C:\PROGRA~1\Kuree\MService.dll>  []
    <DelayRun><C:\WINDOWS\system\2ced4480.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    <WinlogonNotify: AtiExtEvent><Ati2evxx.dll>  [ATI Technologies Inc.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <ATIModeChange><; Ati2mdxx.exe>  [ATI Technologies, Inc.]
    <ATIPTA><; "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe">  [ATI Technologies, Inc.]
    <helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  []
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <SoundMan><; SOUNDMAN.EXE>  [Avance Logic, Inc.]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <WangWang><; "d:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE">  [淘宝(中国)软件有限公司]
    <yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">  [Yahoo!]
    <YLive.exe><; C:\PROGRA~1\Yahoo!\Assistant\YLive.exe>  [ ]
    <YOKAssiant><; Rundll32.exe C:\PROGRA~1\YOK.com\SuperSearch\YOK_SuperSearch.dll,YOKAssiant>  [www.YOK.com]
最后编辑2006-08-22 17:03:16
分享到:
gototop
 

正在运行的进程
[PID: 604][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 668][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 696][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\Ati2evxx.dll]  <ATI Technologies Inc.><6.14.10.4119>
[PID: 740][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 752][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 904][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4119>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
[PID: 920][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1012][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1100][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1180][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1324][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1476][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1724][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4119>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
[PID: 1836][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\PROGRA~1\YOK.com\SuperSearch\YOK_SuperSearch.dll]  <www.YOK.com><2.0.1.7>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\PROGRA~1\3721\alrex.dll]  <><1, 0, 1, 1001>
    [C:\DOCUME~1\袁星\LOCALS~1\Temp\themeadp.nls]  <N/A><N/A>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\PROGRA~1\Yahoo!\Assistant\YAlive.dll]  <><2, 0, 6, 1033>
    [C:\PROGRA~1\Yahoo!\Assistant\Yalliveex.dll]  < ><2, 0, 1, 1007>
    [C:\PROGRA~1\3721\autolive.dll]  <><1, 1, 7, 1326>
    [C:\PROGRA~1\3721\alLiveEx.dll]  < ><1, 0, 3, 1006>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
[PID: 1936][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll]  <北京三七二一科技有限公司><1, 0, 3, 6>
    [C:\WINDOWS\DOWNLO~1\cnsio.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
[PID: 1948][C:\Program Files\CNNIC\Cdn\cdnup.exe]  <><2, 4, 0, 4>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdntdns.dll]  <CNNIC><2, 2, 0, 3>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
[PID: 1976][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\PROGRA~1\3721\autolive.dll]  <><1, 1, 7, 1326>
    [C:\PROGRA~1\3721\notifier.dll]  <><1, 0, 0, 5>
    [C:\PROGRA~1\3721\alLiveEx.dll]  < ><1, 0, 3, 1006>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
[PID: 180][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
[PID: 576][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 376][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1368][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
gototop
 

[C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
[PID: 1760][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1320][C:\PROGRA~1\Kuree\kpupdate.exe]  <N/A><N/A>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 384][C:\PROGRA~1\Yahoo!\Assistant\ylive.exe]  < ><2, 0, 0, 1002>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\PROGRA~1\Yahoo!\Assistant\YAlive.dll]  <><2, 0, 6, 1033>
    [C:\PROGRA~1\Yahoo!\Assistant\Yalliveex.dll]  < ><2, 0, 1, 1007>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\Assistant\ynotifier.dll]  <><1, 0, 0, 5>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 664][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\b921edd\1.dll]  <千橡互联><3, 0, 1, 0>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\WINDOWS\b921edd\3.dll]  <千橡互联><3, 0, 1, 0>
    [C:\WINDOWS\b921edd\4.dll]  <千橡互联><3, 0, 1, 0>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 2440][D:\Program Files\TheWorld\TheWorld.exe]  <Phoenix Studio><1, 2, 3, 5>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\DOWNLO~1\OL2005.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\RavWeb\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\RavWeb\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\RavWeb\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\RavWeb\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\RavWeb\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\RavWeb\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\RavWeb\MVEngine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
    [C:\Program Files\Rising\RavWeb\Engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\RavWeb\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\RavWeb\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\RavWeb\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\RavWeb\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 14>
    [C:\Program Files\Rising\RavWeb\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\RavWeb\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\RavWeb\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\RavWeb\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\RavWeb\ExtMail.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Rising\RavWeb\ExtFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Rising\RavWeb\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\RavWeb\ScanNet.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRA~1\YOK.com\SuperSearch\YOK_SuperSearch.dll]  <www.YOK.com><2.0.1.7>
    [C:\Program Files\Rising\RavWeb\ScanElf.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1060][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  <Thunder Networking Technologies,LTD><5.3.0.220>
    [C:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
    [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 4, 71>
    [C:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  <><1, 0, 2, 1>
    [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  <N/A><N/A>
    [C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 15>
    [C:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 148>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  <Thunder Networking Technologies,LTD><2, 1, 0, 18>
    [C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  < ><1, 0, 0, 11>
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll]  < ><2, 3, 0, 37>
    [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  <Thunder Networking Technologies,LTD><1, 0, 3, 8>
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 55>
    [C:\WINDOWS\system32\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\PROGRA~1\YOK.com\SuperSearch\YOK_SuperSearch.dll]  <www.YOK.com><2.0.1.7>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 3392][D:\Program Files\PPLive\PPLive.exe]  <><1, 0, 0, 1>
    [D:\Program Files\PPLive\PPH.dll]  <N/A><N/A>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\common.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SynacastEWA.OCX]  <Synacast><1, 2, 35, 0>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SynacastList.OCX]  <><1, 0, 0, 0>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\FWUpnp.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\PP\kom.dll]  <Synacast Corp.><1, 1, 0, 8>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\PP\EROC.DLL]  <Synacast Corp.><1, 1, 9, 4>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\PP\TEN.DLL]  <Synacast><1, 1, 0, 8>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\PP\GAL.DLL]  <Synacast><1, 1, 0, 8>
    [C:\PROGRA~1\COMMON~1\Synacast\SynaLive\PP\MIR.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 4000][d:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
[PID: 3568][C:\DOCUME~1\袁星\LOCALS~1\Temp\Rar$EX02.734\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\PROGRA~1\Yahoo!\Assistant\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 1, 0, 1325>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 6>
    [C:\WINDOWS\system32Key.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
gototop
 

这个病毒我用瑞星杀了好几遍了,还是没有杀掉。希望大家能帮帮忙。
gototop
 

先把

3721
“优客搜索助手”
“中国互联网信息中心CNNIC出品的中文域名及中文邮件客户端”

删除了

以下可能是木马:
<SysTime><C:\PROGRA~1\WinKld\WinKld.dll> []
<webwork><C:\WINDOWS\webwork\webwork.dll> []
<DelayRun><C:\WINDOWS\system\2ced4480.dll> []
gototop
 

不好意思,我是电脑白痴,请问怎么删?我把病毒写错了Trojan.Clicker.Agent.abv
gototop
 

我现在再线上,希望高手帮帮忙。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT