瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 一连网就自动出现CMD.EXE,而且严重占用内存(出现新问题)

1   1  /  1  页   跳转

一连网就自动出现CMD.EXE,而且严重占用内存(出现新问题)

一连网就自动出现CMD.EXE,而且严重占用内存(出现新问题)

问题一开始是这样的,发现有两个SMSS.EXE,结果一时性起用费尔那个木马清除机把wingdows下的smss.exe杀掉,好,原来以为OK了,结果一连网过一会就出现cmd.exe,一次我看着它出现,先是1.exe然后转瞬变成了cmd.exe,占用内存很多,60%左右吧,关掉一次好像就不再出现了
问此为何毒?如何清除?谢谢
最后编辑2006-08-21 22:46:57
分享到:
gototop
 

请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
gototop
 

2006-08-21,21:54:15

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <nod32kui><"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE>  [Eset ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{EFAE7B4A-FA39-4818-ACAC-6B6D851CEFF4}><C:\Program Files\Internet Explorer\WinHook.sys>  []
    <{288BD9BD-F0DC-46B1-81B5-2B61DF8077CE}><C:\WINDOWS\system32\1.dLl>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <MsnMsgr><; >  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]

==================================
启动文件夹
服务
[NOD32 Kernel Service / NOD32krn]
  <"C:\Program Files\Eset\nod32krn.exe"><Eset>

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files of Downloads\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~3\FLASHGET\jccatch.dll, Amaze Soft>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~3\FLASHGET\flashget.exe, Amaze Soft>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~3\FLASHGET\fgiebar.dll, Amaze Soft>
[Shockwave ActiveX Control]
  {233C1507-6A77-46A4-9443-F871F945D258} <C:\WINDOWS\system32\Macromed\Director\SwDir.dll, Adobe Systems, Inc.>
[MSN Photo Upload Tool]
  {4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files of Downloads\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~3\FLASHGET\jccatch.dll, Amaze Soft>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
  <C:\Program Files of Downloads\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files of Downloads\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files of Downloads\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files of Downloads\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files of Downloads\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files of Downloads\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 676][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 756][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 780][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 824][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 836][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
[PID: 988][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1032][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
[PID: 1184][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
[PID: 1228][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
[PID: 1364][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
[PID: 1636][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1844][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Internet Explorer\WinHook.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\1.dLl]  <N/A><N/A>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\PROGRA~3\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\WINDOWS\system32\icm32.dll]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\Eset\nodshex.dll]  <N/A><N/A>
[PID: 1956][C:\Program Files\Eset\nod32kui.exe]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\nod32rui.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\1.dLl]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\WinHook.sys]  <N/A><N/A>
    [C:\Program Files\Eset\pu_amon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_amon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pu_dmon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_dmon.dll]  <N/A><N/A>
    [C:\Program Files\Eset\pu_emon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_emon.dll]  <N/A><N/A>
    [C:\Program Files\Eset\pu_imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
    [C:\Program Files\Eset\pu_nod32.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_nod32.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pu_upd.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_upd.dll]  <N/A><N/A>
[PID: 1964][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\1.dLl]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\WinHook.sys]  <N/A><N/A>
[PID: 1332][C:\Program Files\Eset\nod32krn.exe]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\nod32krr.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\ps_amon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_amon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\ps_dmon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_dmon.dll]  <N/A><N/A>
    [C:\Program Files\Eset\ps_emon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_emon.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
    [C:\Program Files\Eset\ps_nod32.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_nod32.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\ps_upd.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_upd.dll]  <N/A><N/A>
[PID: 1268][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 740][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
[PID: 3460][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2472][C:\Program Files\Maxthon\Maxthon.exe]  <Maxthon International Ltd.><1, 5, 6, 42>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\Program Files\Internet Explorer\WinHook.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\1.dLl]  <N/A><N/A>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\upengine.dll]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\WINDOWS\system32\Macromed\Common\SwSupport.dll]  <Adobe Systems, Inc.><10.1.3r18>
[PID: 1540][C:\Documents and Settings\songyang1984\桌面\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\Internet Explorer\WinHook.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\1.dLl]  <N/A><N/A>
    [C:\WINDOWS\system32\imon.dll]  <Eset ><2, 51, 23 >
    [C:\Program Files\Eset\pr_imon.dll]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

报告一次贴完的,先谢1楼的朋友
gototop
 

打开sreng 启动项 注册表 删除<{EFAE7B4A-FA39-4818-ACAC-6B6D851CEFF4}><C:\Program Files\Internet Explorer\WinHook.sys> []
<{288BD9BD-F0DC-46B1-81B5-2B61DF8077CE}><C:\WINDOWS\system32\1.dLl> []
重其后删除C:\Program Files\Internet Explorer\WinHook.sys
C:\WINDOWS\system32\1.dLl
gototop
 

好, 去删掉了
先谢
gototop
 

问题继续
删除的时候提示系统文件,不敢删,移到了桌面
另,我在system32下发现了如下隐藏的文件,帮我看看,哪些DLL是有用的,谢谢
还有system32下有个dllcache的隐藏文件夹,里面是基本和system32里面一样的,有400+M想删,不知是否可行,谢谢

附件附件:

下载次数:601
文件类型:image/pjpeg
文件大小:
上传时间:2006-8-21 22:37:06
描述:



gototop
 

忘了说了两个WINHOOK是在C:\Program Files\Internet Explorer下面的...
gototop
 

搞不懂MANIFEST的后缀是什么?谢谢
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT