瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中木马了,但是不知道是什么病毒咯

12   1  /  2  页   跳转

中木马了,但是不知道是什么病毒咯

中木马了,但是不知道是什么病毒咯

同事的电脑中木马了
瑞星已经不能用了
还有什么卡卡助手拉,360安全卫士啊都安装不上去
这个怎么办呀
最后编辑2006-11-22 16:23:00
分享到:
gototop
 

请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。

下载地址
http://www.kztechs.com/sreng/sreng2.zip

gototop
 

2006-11-16,13:09:19

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows 98 SE  -

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <msnmsgr><"C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background>  [Microsoft Corporation]
    <Microsoft Winshell.exe><C:\WINDOWS\Microsoft Winshell.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <internat.exe><internat.exe>  [N/A]
    <ScanRegistry><C:\WINDOWS\scanregw.exe /autorun>  [Microsoft Corporation]
    <SystemTray><SysTray.Exe>  [Microsoft Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <RsCcenter><"D:\Program Files\Rising\Rav\CCenter.exe">  [Beijing Rising Technology Co., Ltd.]
    <RavMond><"D:\Program Files\Rising\Rav\RavMond.exe">  [Beijing Rising Technology Co., Ltd.]
    <RavMon><"D:\Program Files\Rising\Rav\RavMon.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <WinWrCup><C:\WINDOWS\WINCUP\WINCUP.EXE -R>  [MsWinCup]
    <stdupnet><C:\WINDOWS\rundll32.exe C:\WINDOWS\SYSTEM32\STDUPNET.DLL,Service -s>  [ ]
    <VisionService><C:\WINDOWS\rundll32.exe C:\PROGRA~1\VISION\VISVER.DLL,Service>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\SYSTEM\New York.scr>  [Stardust Software]

==================================
启动文件夹
N/A

==================================
服务
N/A

==================================
驱动程序
N/A

==================================
浏览器加载项
[NetAnts.IE.Monitor]
  {57E91B41-F40A-11D1-B792-444553540000} <C:\PROGRAM FILES\NETANTS\ANTAPI.DLL, $>
[Vision]
  {6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\VISION\vision.dll, >
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YPHTB.DLL, N/A>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YDRAGS~1.DLL, N/A>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[上网助手]
  {BB936323-19FA-4521-BA29-ECA6A121BC78} <C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL, 3721>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[]
  {57E91B47-F40A-11D1-B792-444553542001} <D:\WINDOWS优化大师.EXE, N/A>
[中国移动在线]
  {CD67F990-D8E9-11d2-98FE-00C0F0318AFF} <http://www.yhyweb.com, N/A>
[ZDNet]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <, N/A>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\WINDOWS\SYSTEM\IEPLUGIN.DLL, $>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE, TENCENT>
[NetAnts]
  {57E91B47-F40A-11D1-B792-444553540000} <C:\PROGRA~1\NETANTS\NetAnts.exe,  >
[MMSAssistMenu]
  {6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\VISION\VISVER.DLL, >
[江民在线杀毒]
  {06926B30-424E-4f1c-8EE3-543CD96573DC} <http://online.jiangmin.com/online.asp, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8.OCX, Macromedia, Inc.>
[GlobalEnglish Learning Technology]
  {3A5A2021-0895-11D2-8817-0060089E0724} <C:\PROGRAM FILES\GLOBALENGLISH\CTRL.DLL, GlobalEnglish>
[Ppinstall Control]
  {CF051549-EDE1-40F5-B440-BCD646CF2C25} <C:\WINDOWS\DOWNLO~1\PPINST~1.OCX, 网易 NetEase>
[SetupOne.SetupOneCtl]
  {AA7F552B-B6BE-11D4-AE10-0080C8E1DB8D} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\SETUPONE.OCX, hgjg>
[SetupTwo.SetupTwoCtl]
  {0802E203-B302-11D4-AE10-0080C8E1DB8D} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\SETUPTWO.OCX, hgjg>
[Print Control]
  {3C38FB11-C9DF-4AF2-ACCC-9E682A1CC365} <C:\WINDOWS\SYSTEM\ZFMPRINT05.DLL, 尊网商通资讯科技有限公司>
[VqqSpeedDlProxy Class]
  {F138084D-84D7-48CD-BEA8-04772457516E} <C:\WINDOWS\VQQSDL.DLL, Tencent>
[Submit Class]
  {A3CD7F74-93C9-4BC4-B892-CCDF1514F714} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\SAFEIN.DLL, Beijing eChannels Century Technology Co.,Ltd>
[KvScanOnline Control]
  {EF6205C1-3F17-4829-BCB5-1336ED89E356} <C:\WINDOWS\SYSTEM\KVDOWN.OCX, dreamersoft>
[添加到QQ自定义面板]
  <C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm, N/A>
[&Download by NetAnts]
  <C:\PROGRA~1\NETANTS\NAGet.htm, N/A>
[Download &All by NetAnts]
  <C:\PROGRA~1\NETANTS\NAGetAll.htm, N/A>
[  >> 彩信发送 <<]
  <res://C:\PROGRAM FILES\MMSASSIST\MMSASS~1.DLL/mms.htm, N/A>
[上传到QQ网络硬盘]
  <C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm, N/A>
[&Google Search]
  <res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html, N/A>
[&Translate English Word]
  <res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmwordtrans.html, N/A>
[Cached Snapshot of Page]
  <res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html, N/A>
[Similar Pages]
  <res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html, N/A>
[Backward Links]
  <res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html, N/A>
[Translate Page into English]
  <res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html, N/A>
[>>彩信发送<<]
  <res://C:\PROGRAM FILES\VISION\VISVER.DLL/mms.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 4294940715][C:\WINDOWS\SYSTEM\MPREXE.EXE]  [Microsoft Corporation, 4.10.1998]
[PID: 4294966975][D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 4294863091][C:\WINDOWS\WINCUP\WINCUP.EXE]  [MsWinCup, 1, 0, 0, 0]
    [C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL]  [3721, 1, 0, 0, 2]
    [C:\PROGRAM FILES\VISION\VISION.DLL]  [, 1, 2, 0, 7]
    [C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB 文件夹\MSONSEXT.DLL]  [N/A, N/A]
    [C:\PROGRAM FILES\WINRAR\RAREXT.DLL]  [N/A, N/A]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\PROGRAM FILES\3721\SKE\CONTMENU.DLL]  [N/A, N/A]
    [C:\PROGRAM FILES\WINZIP\WZSHLSTB.DLL]  [WinZip Computing, Inc., 3.0 (32-bit)]
    [D:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\PROGRAM FILES\NETANTS\ANTAPI.DLL]  [$, 1, 25, 1, 0]
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  [N/A, N/A]
    [C:\WINDOWS\SYSTEM\RAVEXT.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[PID: 4294892299][C:\WINDOWS\EXPLORER.EXE]  [Microsoft Corporation, 4.72.3110.1]
[PID: 4294818063][C:\WINDOWS\SYSTEM\RPCSS.EXE]  [Microsoft Corporation, 4.71.2900]
[PID: 4294732087][C:\INTERNAT.EXE]  [Microsoft Corporation, 4.10.2222]
[PID: 4294729691][C:\WINDOWS\SYSTEM\SYSTRAY.EXE]  [Microsoft Corporation, 4.10.2222]
[PID: 4294722727][C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]  [RealNetworks, Inc., 0.1.0.3427]
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  [N/A, N/A]
    [C:\WINDOWS\SYSTEM\DCIMAN32.DLL]  [Intel(R) Corp., Microsoft Corp., 4.03.1998]
[PID: 4294751127][C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE]  [Microsoft Corporation, 7.0.0816]
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  [N/A, N/A]
[PID: 4294768159][C:\WINDOWS\MICROSOFT WINSHELL.EXE]  [N/A, N/A]
    [C:\WINDOWS\SYSTEM\DCIMAN32.DLL]  [Intel(R) Corp., Microsoft Corp., 4.03.1998]
[PID: 4294699731][C:\WINDOWS\SYSTEM\WMIEXE.EXE]  [Microsoft Corporation, 5.00.1755.1]
    [D:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
    [D:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [D:\PROGRAM FILES\RISING\RAV\NVFILE.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
    [D:\PROGRAM FILES\RISING\RAV\SCANEX.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 32]
    [D:\PROGRAM FILES\RISING\RAV\EXTFILE.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
    [D:\PROGRAM FILES\RISING\RAV\RSUNPACK.DLL]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 20]
    [D:\PROGRAM FILES\RISING\RAV\UNEXE.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [D:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
    [D:\PROGRAM FILES\RISING\RAV\ENGINE.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 35]
    [D:\PROGRAM FILES\RISING\RAV\SPAMENG.DLL]  [N/A, 18, 0, 0, 6]
    [D:\PROGRAM FILES\RISING\RAV\MAILMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\PROGRAM FILES\RISING\RAV\MEMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [D:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL]  [rising, 18, 0, 0, 2]
    [D:\PROGRAM FILES\RISING\RAV\REGMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [D:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [D:\PROGRAM FILES\RISING\RAV\SCANNER.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 33]
    [D:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL]  [Beijing Rising Technology Co., Ltd., 18, 1, 0, 12]
    [D:\PROGRAM FILES\RISING\RAV\RSLOG.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [D:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  [rising, 18, 0, 0, 1]
[PID: 4294831399][D:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE]  [Beijing Rising Technology Co., Ltd., 18, 0, 1, 47]
    [D:\PROGRAM FILES\RISING\RAV\BWLIST.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  [rising, 18, 0, 0, 1]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [D:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[PID: 4294690395][D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]  [Beijing Rising Technology Co., Ltd., 18, 0, 1, 39]
    [D:\PROGRAM FILES\RISING\RAV\BWLIST.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
[PID: 4294530823][C:\WINDOWS\DESKTOP\SRENG\SRENG.EXE]  [Smallfrogs Studio, 2.2.6.605]

==================================
文件关联
.TXT  Error. [NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [C:\WINDOWS\winhlp32.exe %1]
.INI  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MS.w95.spi.osp
    C:\WINDOWS\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.tcp
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.udp
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.raw
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.rsvptcp
    C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.rsvpudp
    C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
gototop
 

高手帮忙看一下吧
谢谢咯
gototop
 

现在还有两个问题
一是瑞星卡卡助手没法安上去
还有一个是当打开我的电脑里面的控制面板里面的东西时,就会跳出来一个框,写着
找不到C;\WINDOWS\RUNDLL32.EXE(或他的组件之一)
gototop
 

高手们能不能解答一下咯
gototop
 

98的系统  太老了 现在很多新的软件已经不能安装在98上了 最好更新一下系统
gototop
 

可是现在这种情况有没有的解决啊。
gototop
 

C:\WINDOWS\WINCUP\WINCUP.EXE
瑞星的首页有相关的链接
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT