瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求救2 日志扫上 看看是什么病毒(1)

1   1  /  1  页   跳转

求救2 日志扫上 看看是什么病毒(1)

求救2 日志扫上 看看是什么病毒(1)

[CODE]

2007-02-24,21:11:10

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">  [(Verified)Yahoo! China]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\Qktsk.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg]
    <WinlogonNotify: cryptimg><cryptimg.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc]
    <WinlogonNotify: rpcc><C:\WINDOWS\system32\rpcc.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [N/A]

==================================
启动文件夹
[WanSo]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\WanSo.lnk --> C:\WINDOWS\system32\rundll32.exe [Microsoft Corporation]><N>
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.LNK --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[219829DA / 219829DA][Stopped/]
  <2 - 系统找不到指定的文件。
><N/A>
[Client IP-IPX / Client IP-IPX][Stopped/Disabled]
  <"C:\WINDOWS\system32\svchosts.exe" -e te-110-12-0000327><N/A>
[FLEXnet Licensing Service / FLEXnet Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"><Macrovision Europe Ltd.>
[Gentad / Gentad][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\gentad\gentad.dll>< >
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Office Backup Engine / Investor][Running/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\vugsf.dll><Microsoft Corporation>
[Std pvar Service / pvar][Running/Auto Start]
  <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\COMMON~1\hnvj\uxfw.dll,Service -s><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Security Machine Manager / SOCEESe][Stopped/Auto Start]
  <C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\HNTHD.DLL,Export 1087><N/A>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[acpidisk / acpidisk][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[ADProt / ADProt][Stopped/System Start]
  <\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CdaC15BA / CdaC15BA][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\CdaC15BA.SYS><Macrovision Europe Ltd>
[CnsMinKP / CnsMinKP][Running/Boot Start]
  <\SystemRoot\system32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[Yamaha DS1 Audio Driver (WDM) / ds1][Stopped/Manual Start]
  <system32\drivers\ds1wdm.sys><Yamaha Corp.>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[fkwld / fkwld][Stopped/Disabled]
  <???\C:\WINDOWS\SYSTEM32\DRIVERS\FKWLD.SYS><N/A>
[hidproc / hidproc][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\hidproc.sys><Microsoft Corporation>
[HookCont / HookCont][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[hookreg / hookreg][Running/Manual Start]
  <\??\C:\Program Files\Rising\Rav\hookreg.sys><>
[ieyk / ieyko][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\ieyko.sys><N/A>
[iseineh / iseineh][Running/Boot Start]
  <\SystemRoot\system32\drivers\iseineh.sys><N/A>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Stopped/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[oqanehe / oqanehe][Running/Boot Start]
  <\SystemRoot\system32\drivers\oqanehe.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[pzrdvqt / pzrdvqt][Running/Boot Start]
  <\SystemRoot\system32\drivers\pzrdvqt.sys><N/A>
[qqimyj2 / qqimyj25][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\qqimyj25.sys><N/A>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[S3SavageNB / S3SavageNB][Running/Manual Start]
  <system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
[SAMDRV / SAMDRV][Running/Boot Start]
  <\SystemRoot\system32\SAMDRV.sys><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaidexp.sys><VIA Technologies, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>
[zzsquqi / zzsquqi][Running/Boot Start]
  <\SystemRoot\system32\drivers\zzsquqi.sys><N/A>
[00005fc4 / 00005fc4][Stopped/]
  <2 - 系统找不到指定的文件。
><N/A>
[mwwppdm / mwwppdm][Running/Boot Start]
  <\SystemRoot\system32\drivers\mwwppdm.sys><N/A>
[NPPTNT2 / NPPTNT2][Running/Manual Start]
  <\??\C:\WINDOWS\system32\npptNT2.sys><INCA Internet Co., Ltd.> (未完)
最后编辑2007-02-24 22:01:04
分享到:
gototop
 

大概看了下,应该是中木马了,没时间看了,要下班了...明天再来帮你看好了..不好意思.
gototop
 

【回复“logicl”的帖子】谢谢
gototop
 

【回复“小菜菜啊”的帖子】 总共我扫了日志分了3个帖子发上去的这个还没完上面还有两个帖子
gototop
 

如果不用上网助手的话建议用360安全卫士清除
gototop
 

<Userinit><C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\Qktsk.exe> [N/A]
用SREng编辑,删除C:\WINDOWS\system32\userinit.exe,后面的exe

删除启动项
<WinlogonNotify: rpcc><C:\WINDOWS\system32\rpcc.dll> [N/A]


服务
[219829DA / 219829DA][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[Client IP-IPX / Client IP-IPX][Stopped/Disabled]
<"C:\WINDOWS\system32\svchosts.exe" -e te-110-12-0000327><N/A>
[Gentad / Gentad][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\gentad\gentad.dll>< >

后面几个服务不敢确定..
不懂用SREng看:http://forum.ikaka.com/topic.asp?board=28&artid=8270267


删除文件:
c:\WINDOWS\Qktsk.exe
C:\WINDOWS\system32\rpcc.dll

建议用强制删除工具 PowerRMV 下载地址: http://post.baidu.com/f?kz=158203765
分别填入下面的文件(包括完整的路径) ,勾选“抑止杀灭对象再次生成”,点杀灭 【有找不到提示的请忽略错误继续】
gototop
 

C:\WINDOWS\system32\rundll32.exe

这个别删,系统文件!
gototop
 

【回复“spiritfire”的帖子】
搞错了...
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT