瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了Trojan.Vundo.w 同Backdoor.IRCBot.dfj毒啊,杀了又有啊

1   1  /  1  页   跳转

中了Trojan.Vundo.w 同Backdoor.IRCBot.dfj毒啊,杀了又有啊

中了Trojan.Vundo.w 同Backdoor.IRCBot.dfj毒啊,杀了又有啊

另外还有好多啊,都说是WINDOWS下的PE病毒啊,每次杀了后重又有毒,有些就是要手动删啊,删了又有啊,高手们请看我的日志啊

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional  (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <a6b6edb36a5ac12e3c648924c3c698b4><; "D:\下\d120jx210.12012.0.exe" -t 12012.0>  [N/A]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background>  [N/A]
    <Super Rabbit Desktop Search><; ; D:\Program Files\Super Rabbit\新建文件夹\srsearch.exe>  [N/A]
    <Super Rabbit IEPro><D:\Program Files\Super Rabbit\新建文件夹\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <Yahoo! Pager><; >  [N/A]
    <<DLMon>><<>[]>  [N/A]
    <<ipsec>><<rundll32.exe>[]>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>  [北京三七二一科技有限公司]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <CHK><C:\Program Files\isofti corp\BSC宽带支撑系统\checkbsc.exe>  [N/A]
    <BigDogPath><; C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>  [N/A]
    <iDuba Personal FireWall><; >  [N/A]
    <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <ISC><; >  [N/A]
    <ISC_UpDate><; >  [N/A]
    <KAVRun><; >  [N/A]
    <KpopMon><; >  [N/A]
    <Kulansyn><; >  [N/A]
    <PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <RfwMain><; "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <SoundMan><; SOUNDMAN.EXE>  [N/A]
    <SysExplr><; >  [N/A]
    <WDM><; MSWDM.EXE>  [N/A]
    <BWC><C:\Program Files\isofti corp\BSC宽带支撑系统\upgrade.exe>  [N/A]
    <Search_hongjie><>  [N/A]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <Services><C:\prosys32.exe>  [N/A]
    <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <WDM><; MSWDM.EXE>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><c:\windows\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll>  [北京三七二一科技有限公司]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{9A36CEDC-2619-43F0-8108-50A321AD3057}><C:\WINDOWS\System32\qomnlki.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomnlki]
    <WinlogonNotify: qomnlki><qomnlki.dll>  [N/A]
最后编辑2006-11-15 18:11:24
分享到:
gototop
 

启动文件夹
N/A

==================================
服务
[C-DillaSrv / C-DillaSrv]
  <C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE><C-Dilla Ltd>
[Canon NetSpot Suite Service / Canon NetSpot Suite Service]
  <C:\Program Files\Canon\VDC\AuVdc.exe><CANON INC.>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IMAPI CD-Burning COM Service / ImapiService]
  <C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[Rising Proxy  Service / RfwProxySrv]
  <d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><NetGroup - Politecnico di Torino>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[WINLASS / WINLASS]
  <><N/A>

==================================
驱动程序
[468623 / 468623]
  <\SystemRoot\System32\drivers\468623.sys><N/A>
[a0 / a0]
  <\SystemRoot\\SystemRoot\System32\drivers\468623.sys><N/A>
[Service for Avance AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><N/A>
[ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter / AN983]
  <System32\DRIVERS\AN983.sys><ADMtek Incorporated.>
[ati2mpaa / ati2mpaa]
  <System32\DRIVERS\ati2mpaa.sys><ATI Technologies Inc.>
[atimtag / atimtag]
  <System32\DRIVERS\atimtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[C-Dilla / C-Dilla]
  <\??\C:\WINDOWS\System32\drivers\CDANT.SYS><Macrovision>
[CnsMinKP / CnsMinKP]
  <\SystemRoot\System32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[Intel(R) PRO Adapter Driver / E100B]
  <System32\DRIVERS\e100b325.sys><Intel Corporation>
[ExpScaner / ExpScaner]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
  <\??\D:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[MEMSCAN / MEMSCAN]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
  <\??\d:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[NetGroup Packet Filter Driver / NPF]
  <system32\drivers\npf.sys><Politecnico di Torino>
[npkcrypt / npkcrypt]
  <\??\D:\Tencent\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv]
  <\??\D:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS]
  <\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[S3Psddr / S3Psddr]
  <System32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
[Secdrv / Secdrv]
  <System32\DRIVERS\secdrv.sys><N/A>
[SKNFW / SKNFW]
  <\??\C:\WINDOWS\System32\Drivers\SKNFW.sys><N/A>
[Sparrow / Sparrow]
  <\SystemRoot\System32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[VIA AGP Filter / viaagp1]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[ViaIde / ViaIde]
  <\SystemRoot\System32\DRIVERS\viaidexp.sys><VIA Technologies, Inc.>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio]
  <system32\drivers\viaudios.sys><VIA Technologies, Inc.>
gototop
 

==================================
浏览器加载项
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\Super Rabbit\新建文件夹\haokanbar.dll, Xiang Feng Technology>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.>
[]
  {9A36CEDC-2619-43F0-8108-50A321AD3057} <C:\WINDOWS\System32\qomnlki.dll, N/A>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[Yahoo 3.5G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[名品折扣]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[雅虎WIDGET]
  {6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Tencent\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Tencent\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[金山毒霸]
  {A9BE2902-C447-420A-BB7F-A5DE921E6138} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\Super Rabbit\新建文件夹\haokanbar.dll, Xiang Feng Technology>
[WebActivater Control]
  {3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINDOWS\System32\WEBACT~1.OCX, QQ>
[YupIEBarExtObj Class]
  {8811D177-42CE-4438-B7D4-38F6A4F1D327} <C:\WINDOWS\Downloaded Program Files\YupIEBarExt3.dll, >
[Qzone Media Tools]
  {AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} <D:\Tencent\VQQPLA~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[My99Launch Control]
  {D57A1919-CB3C-461C-8F34-A87A1CD9127E} <C:\WINDOWS\System32\99Launch.ocx, >
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
  <, N/A>
[&使用迅雷下载全部链接]
  <, N/A>
[上传到QQ网络硬盘]
  <D:\Tencent\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <D:\Tencent\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Tencent\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <, N/A>
gototop
 

正在运行的进程
[PID: 500][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\qomnlki.dll]  [N/A, N/A]
[PID: 624][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 636][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 796][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 844][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 876][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1032][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1048][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1072][C:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 1, 47]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 18, 1, 0, 12]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 33]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\HookWeb.dll]  [rising, 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [C:\Program Files\Rising\Rav\MailMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 35]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 32]
    [C:\Program Files\Rising\Rav\RSUnpack.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 20]
    [C:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[PID: 1116][d:\program files\rising\rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 30]
    [d:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 12]
    [d:\program files\rising\rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 6]
    [d:\program files\rising\rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 21]
    [d:\program files\rising\rfw\MonDrv.dll]  [rs, 1, 0, 0, 4]
    [d:\program files\rising\rfw\ProcLib.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 9]
[PID: 1336][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\AUCJLMNT.DLL]  [CANON INC., 5.0.0.4]
    [C:\WINDOWS\system32\NBLMC.DLL]  [CANON INC., 7.0.0.0]
    [C:\Program Files\Canon\VDCP\AuSpMsngr.dll]  [CANON INC., 3, 0, 0, 0]
[PID: 1472][C:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1548][C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE]  [C-Dilla Ltd, 3.24.010]
[PID: 1572][C:\Program Files\Canon\VDC\AuVdc.exe]  [CANON INC., 3, 0, 0, 2]
gototop
 

[C:\Program Files\Canon\VDC\AuSrvc.dll]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AUPAM.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuPMPublisher.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuIpc.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuCrSpMsngr.crp]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuPaSnmp.dll]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuSnmp.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuTrans.dll]  [CANON INC., 3, 1, 1, 0]
    [C:\Program Files\Canon\VDC\AUOIM.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuPaCpca.dll]  [CANON INC., 3, 1, 0, 1]
    [C:\Program Files\Canon\VDC\aucpca.dll]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuPaCjl.dll]  [CANON INC., 3, 1, 0, 1]
    [C:\Program Files\Canon\VDC\AUCJLPRS.dll]  [CANON INC., 2, 5, 0, 1]
    [C:\Program Files\Canon\VDC\AuPaPjl.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuLocalt.dll]  [CANON INC., 2, 4, 0, 0]
    [C:\Program Files\Canon\VDC\AUSS.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\WINDOWS\System32\NBLocalt.dll]  [CANON INC., 5, 5, 0, 1]
    [C:\WINDOWS\System32\NBcbtNT.dll]  [CANON INC., 5, 5, 0, 1]
    [C:\Program Files\Canon\VDC\NsCanon.oim]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\Ns1213.oim]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\NsAT.oim]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\NsCIS.oim]  [CANON INC., 1, 1, 0, 0]
    [C:\Program Files\Canon\VDC\NsHR.oim]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\NsPRT.oim]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\NsTR.oim]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuDifDevInfoS.dif]  [CANON INC., 1, 2, 0, 0]
    [C:\Program Files\Canon\VDC\AuDifDevInfo.dll]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuPSCommonS.dll]  [CANON INC., 3, 1, 0, 1]
    [C:\Program Files\Canon\VDC\AuAE.dll]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuDifEventS.dif]  [CANON INC., 1, 2, 0, 0]
    [C:\Program Files\Canon\VDC\AUDIFEVENT.dll]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuDifNbS.dif]  [CANON INC., 2, 5, 0, 0]
    [C:\Program Files\Canon\VDC\AUDIFNB.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AUDIFSYSCON.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuDifSS.dif]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuDifSysconS.dif]  [CANON INC., 2, 5, 0, 0]
    [C:\Program Files\Canon\VDC\AuDscvrS.dif]  [CANON INC., 1, 2, 0, 0]
    [C:\Program Files\Canon\VDC\AUDSCVR.dll]  [CANON INC., 3, 1, 0, 2]
    [C:\Program Files\Canon\VDC\AuKeeperS.dif]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AUKEEPER.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuSnmpDifS.dif]  [CANON INC., 1, 2, 0, 0]
    [C:\Program Files\Canon\VDC\AuFscAccS.fsc]  [CANON INC., 2, 5, 0, 1]
    [C:\Program Files\Canon\VDC\AUFSCACC.dll]  [CANON INC., 3, 1, 0, 1]
    [C:\Program Files\Canon\VDC\AuFscDevMgmtS.fsc]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuFscDevMgmt.dll]  [CANON INC., 1, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuFscResMgmtS.fsc]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuFscResMgmt.dll]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuPauResTool.dll]  [CANON INC.\, 1, 2, 0, 0]
    [C:\Program Files\Canon\VDC\AuFscLogS.fsc]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuFscLog.dll]  [CANON INC., 3, 0, 0, 0]
    [C:\Program Files\Canon\VDC\AuDHLmk.ndh]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuDHSIP.ndh]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuDHSIPX.ndh]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuDHEml.ndh]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuDHIP.ndh]  [CANON INC., 3, 1, 0, 0]
    [C:\Program Files\Canon\VDC\AuDHIPX.ndh]  [CANON INC., 3, 1, 0, 0]
[PID: 1656][C:\WINDOWS\System32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 1980][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 1, 0, 4, 2]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [C:\WINDOWS\System32\qomnlki.dll]  [N/A, N/A]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
    [C:\PROGRA~1\3721\alrex.dll]  [, 1, 0, 1, 1001]
    [C:\PROGRA~1\3721\AutoLive.dll]  [, 1, 1, 8, 1327]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
    [C:\PROGRA~1\baidu\bar\baidubar.dll]  [Baidu.com, Inc., 2, 0, 2, 114]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [d:\PROGRA~1\3721\ske\contmenu.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\JPWB.IME]  [常诚研制, 4.00.950]
[PID: 2024][d:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 48]
    [d:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
    [d:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [d:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 252][C:\WINDOWS\System32\Rundll32.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
    [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll]  [北京三七二一科技有限公司, 1, 0, 3, 7]
    [C:\WINDOWS\DOWNLO~1\cnsio.dll]  [北京三七二一科技有限公司, 1, 0, 2, 8]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
    [C:\WINDOWS\DOWNLO~1\CnsMinEx.dll]  [国风因特软件(北京)有限公司, 1, 0, 3, 5]
[PID: 296][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 344][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3292]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 676][C:\Program Files\isofti corp\BSC宽带支撑系统\checkbsc.exe]  [, 1, 0, 0, 1]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 956][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 968][C:\prosys32.exe]  [N/A, N/A]
[PID: 1024][C:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 1, 39]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
[PID: 1096][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
    [C:\PROGRA~1\3721\AutoLive.dll]  [, 1, 1, 8, 1327]
    [C:\PROGRA~1\3721\notifier.dll]  [, 1, 0, 0, 5]
    [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
[PID: 1364][C:\Program Files\isofti corp\BSC宽带支撑系统\bwc.exe]  [宏杰软件开发有限公司, 2, 1, 9, 1]
    [C:\WINDOWS\System32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 19]
    [C:\WINDOWS\System32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 19]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
[PID: 2544][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
gototop
 

[PID: 120][D:\金信话吧管理专家\Jxsg2003.exe]  [湖南娄底金信电子科技发展有限公限, 1.0.0.0]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
    [C:\Program Files\Common Files\Borland Shared\BDE\IDAPI32.DLL]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\IDR20009.DLL]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\BANTAM.DLL]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\IDPDX32.DLL]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\idsql32.DLL]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\idbat32.DLL]  [N/A, N/A]
[PID: 3772][C:\Program Files\Rising\Rav\Rav.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 75]
    [C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RavUI.Dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 65]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 33]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\RavUIMsg.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 27]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\MVEngine.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
    [C:\Program Files\Rising\Rav\Engine.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 35]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
    [C:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 32]
    [C:\Program Files\Rising\Rav\RSUnpack.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 20]
    [C:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\ExtMail.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 1, 0, 4, 2]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [C:\WINDOWS\System32\qomnlki.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 3020][D:\下\网络电视\陈\SREng2\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 0, 1325]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 8]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
gototop
 

打开SRENG-启动项目-注册表,删除:
<Services><C:\prosys32.exe> [N/A]
打开SRENG-启动项目-驱动,选择隐藏微软的驱动,找到并删除:
[[468623 / 468623]
<\SystemRoot\System32\drivers\468623.sys><N/A>
[a0 / a0]
<\SystemRoot\\SystemRoot\System32\drivers\468623.sys><N/A>


安全模式下删除:
][C:\prosys32.exe] [N/A, N/A]

<\SystemRoot\System32\drivers\468623.sys><N/A>
<\SystemRoot\\SystemRoot\System32\drivers\468623.sys><N/A>
gototop
 

按你的做了,重启后还有病毒啊Trojan.Vundo.w  Trojan.DL.Agent.amb
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT