瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 跪求wntbhaa.exe和lgwubrw.exe如何清除!!

1   1  /  1  页   跳转

跪求wntbhaa.exe和lgwubrw.exe如何清除!!

跪求wntbhaa.exe和lgwubrw.exe如何清除!!

wntbhaa.exe和lgwubrw.exe主要变现: 自动运行复制,自动进优盘,修改图标,封瑞星卡巴斯基等杀毒软件,系统重装后仍不能清除,跪求高手赐教!!!!!!!!!!!!!!!!
最后编辑2007-05-24 00:52:41
分享到:
gototop
 

太长了,只贴一部分吧
[smss.exe]
PID = 0x1b0
CommandLine =
    smss.exe
    0x48580000
    C:\WINDOWS\system32\smss.exe
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT Session Manager
    2005-05-02 04:30:00

    ntdll.dll
    0x7c920000
    C:\WINDOWS\system32\ntdll.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    NT Layer DLL
    2005-05-02 04:30:00




[csrss.exe]
PID = 0x1f0
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
    csrss.exe
    0x4a680000
    c:\windows\system32\csrss.exe
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Client Server Runtime Process
    2005-05-02 04:30:00

    ntdll.dll
    0x7c920000
    C:\WINDOWS\system32\ntdll.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    NT Layer DLL
    2005-05-02 04:30:00

    CSRSRV.dll
    0x75aa0000
    C:\WINDOWS\system32\csrsrv.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Client Server Runtime Process
    2005-05-02 04:30:00

    basesrv.dll
    0x75ab0000
    C:\WINDOWS\system32\basesrv.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT BASE API Server DLL
    2005-05-02 04:30:00

    winsrv.dll
    0x764e0000
    C:\WINDOWS\system32\winsrv.dll
    5.1.2600.2622 (xpsp.050301-1521)
    Microsoft Corporation
    Windows Server DLL
    2005-05-02 04:30:00

    GDI32.dll
    0x77ef0000
    C:\WINDOWS\system32\gdi32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    GDI Client DLL
    2005-05-02 04:30:00

    KERNEL32.dll
    0x7c800000
    C:\WINDOWS\system32\kernel32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT BASE API Client DLL
    2005-05-02 04:30:00

    USER32.dll
    0x77d10000
    C:\WINDOWS\system32\user32.dll
    5.1.2600.2622 (xpsp.050301-1521)
    Microsoft Corporation
    Windows XP USER API Client DLL
    2005-05-02 04:30:00

    LPK.DLL
    0x62c20000
    C:\WINDOWS\system32\lpk.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Language Pack
    2005-05-02 04:30:00

    USP10.dll
    0x73fa0000
    C:\WINDOWS\system32\usp10.dll
    1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Uniscribe Unicode script processor
    2005-05-02 04:30:00

    msvcrt.dll
    0x77be0000
    C:\WINDOWS\system32\msvcrt.dll
    7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT CRT DLL
    2005-05-02 04:30:00

    ADVAPI32.dll
    0x77da0000
    C:\WINDOWS\system32\advapi32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Advanced Windows 32 Base API
    2005-05-02 04:30:00

    RPCRT4.dll
    0x77e50000
    C:\WINDOWS\system32\rpcrt4.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Remote Procedure Call Runtime
    2005-05-02 04:30:00

    sxs.dll
    0x75e00000
    C:\WINDOWS\system32\sxs.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Fusion 2.5
    2005-05-02 04:30:00




[winlogon.exe]
PID = 0x208
CommandLine = winlogon.exe
    winlogon.exe
    0x1000000
    c:\windows\system32\winlogon.exe
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT Logon Application
    2005-05-02 04:30:00

    ntdll.dll
    0x7c920000
    C:\WINDOWS\system32\ntdll.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    NT Layer DLL
    2005-05-02 04:30:00

    kernel32.dll
    0x7c800000
    C:\WINDOWS\system32\kernel32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT BASE API Client DLL
    2005-05-02 04:30:00

    ADVAPI32.dll
    0x77da0000
    C:\WINDOWS\system32\advapi32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Advanced Windows 32 Base API
    2005-05-02 04:30:00

    RPCRT4.dll
    0x77e50000
    C:\WINDOWS\system32\rpcrt4.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Remote Procedure Call Runtime
    2005-05-02 04:30:00

    AUTHZ.dll
    0x77fe0000
    C:\WINDOWS\system32\authz.dll
    5.1.2600.2622 (xpsp.050301-1521)
    Microsoft Corporation
    Authorization Framework
    2005-05-02 04:30:00

    msvcrt.dll
    0x77be0000
    C:\WINDOWS\system32\msvcrt.dll
    7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT CRT DLL
    2005-05-02 04:30:00

    CRYPT32.dll
    0x765e0000
    C:\WINDOWS\system32\crypt32.dll
    5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Crypto API32
    2005-05-02 04:30:00

    USER32.dll
    0x77d10000
    C:\WINDOWS\system32\user32.dll
    5.1.2600.2622 (xpsp.050301-1521)
    Microsoft Corporation
    Windows XP USER API Client DLL
    2005-05-02 04:30:00

    GDI32.dll
    0x77ef0000
    C:\WINDOWS\system32\gdi32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    GDI Client DLL
    2005-05-02 04:30:00

    MSASN1.dll
    0x76db0000
    C:\WINDOWS\system32\msasn1.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    ASN.1 Runtime APIs
    2005-05-02 04:30:00

    NDdeApi.dll
    0x758a0000
    C:\WINDOWS\system32\nddeapi.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Network DDE Share Management APIs
    2005-05-02 04:30:00

    PROFMAP.dll
    0x75890000
    C:\WINDOWS\system32\profmap.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Userenv
    2005-05-02 04:30:00

    NETAPI32.dll
    0x5fdd0000
    C:\WINDOWS\system32\netapi32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Net Win32 API DLL
    2005-05-02 04:30:00

    USERENV.dll
    0x759d0000
    C:\WINDOWS\system32\userenv.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Userenv
    2005-05-02 04:30:00

    PSAPI.DLL
    0x76bc0000
    C:\WINDOWS\system32\psapi.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Process Status Helper
    2005-05-02 04:30:00

    REGAPI.dll
    0x76b90000
    C:\WINDOWS\system32\regapi.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Registry Configuration APIs
    2005-05-02 04:30:00

    Secur32.dll
    0x77fc0000
    C:\WINDOWS\system32\secur32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Security Support Provider Interface
    2005-05-02 04:30:00

    SETUPAPI.dll
    0x76060000
    C:\WINDOWS\system32\setupapi.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows Setup API
    2005-05-02 04:30:00

    VERSION.dll
    0x77bd0000
    C:\WINDOWS\system32\version.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Version Checking and File Installation Libraries
    2005-05-02 04:30:00

    WINSTA.dll
    0x762d0000
    C:\WINDOWS\system32\winsta.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Winstation Library
    2005-05-02 04:30:00

    WINTRUST.dll
    0x76c00000
    C:\WINDOWS\system32\wintrust.dll
    5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Microsoft Trust Verification APIs
    2005-05-02 04:30:00

    IMAGEHLP.dll
    0x76c60000
    C:\WINDOWS\system32\imagehlp.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT Image Helper
    2005-05-02 04:30:00

    WS2_32.dll
    0x71a20000
    C:\WINDOWS\system32\ws2_32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows Socket 2.0 32-Bit DLL
    2005-05-02 04:30:00

    WS2HELP.dll
    0x71a10000
    C:\WINDOWS\system32\ws2help.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows Socket 2.0 Helper for Windows NT
    2005-05-02 04:30:00

    IMM32.DLL
    0x76300000
    C:\WINDOWS\system32\imm32.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows XP IMM32 API Client DLL
    2005-05-02 04:30:00

    LPK.DLL
    0x62c20000
    C:\WINDOWS\system32\lpk.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Language Pack
    2005-05-02 04:30:00

    USP10.dll
    0x73fa0000
    C:\WINDOWS\system32\usp10.dll
    1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Uniscribe Unicode script processor
    2005-05-02 04:30:00

    MSGINA.dll
    0x758d0000
    C:\WINDOWS\system32\msgina.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows NT Logon GINA DLL
    2005-05-02 04:30:00

    SHELL32.dll
    0x7d590000
    C:\WINDOWS\system32\shell32.dll
    6.00.2900.2620 (xpsp.050225-1825)
    Microsoft Corporation
    Windows Shell Common Dll
    2005-05-02 04:30:00

    SHLWAPI.dll
    0x77f40000
    C:\WINDOWS\system32\shlwapi.dll
    6.00.2900.2627 (xpsp.050309-1719)
    Microsoft Corporation
    Shell Light-weight Utility Library
    2005-05-02 04:30:00

    COMCTL32.dll
    0x5d170000
    C:\WINDOWS\system32\comctl32.dll
    5.82 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Common Controls Library
    2005-05-02 04:30:00

    ODBC32.dll
    0x73540000
    C:\WINDOWS\system32\odbc32.dll
    3.525.1117.0 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Microsoft Data Access - ODBC Driver Manager
    2005-05-02 04:30:00

    comdlg32.dll
    0x76320000
    C:\WINDOWS\system32\comdlg32.dll
    6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Common Dialogs DLL
    2005-05-02 04:30:00

    comctl32.dll
    0x77180000
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
    6.0 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    User Experience Controls Library
    2005-05-02 04:30:00

    odbcint.dll
    0x20000000
    C:\WINDOWS\system32\odbcint.dll
    3.525.1117.0 built by: (_sqlbld)
    Microsoft Corporation
    Microsoft Data Access - ODBC Resources
    2005-05-02 04:30:00

    SHSVCS.dll
    0x76e10000
    C:\WINDOWS\system32\shsvcs.dll
    6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows Shell Services Dll
    2005-05-02 04:30:00

    sfc.dll
    0x76b80000
    C:\WINDOWS\system32\sfc.dll
    5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    Microsoft Corporation
    Windows File Protection
    2005-05-02 04:30:00

    sfc_os.dll
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT