查看: 3813|回复: 12
收起左侧

新近中招,请各位高手帮帮眼orz

[复制链接]
momowie
发表于 2007-9-24 19:36:01 | 显示全部楼层 |阅读模式
之前浏览网页时卡巴报了几次木马frojan,generic(陆续有sys86.exe,sys88.exe,sys281.exe,sys63.exe等)但是手动删除文件并修改注册表后重启联网后仍然会出现病毒提示,并且CPU使用一直处于80%以上,下面是sreng的扫描日志,请各位大人帮忙看看,orz
  1. 2007-09-24,19:08:37

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.       [(Verified)Microsoft Windows Publisher]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  22.     <!AVG Anti-Spyware><"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [(Verified)GRISOFT LTD]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  24.       [(Verified)Microsoft Windows Publisher]
  25.       [(Verified)Microsoft Windows Publisher]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  27.     <>  [N/A]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.       [(Verified)Microsoft Windows Publisher]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  31.     <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}>  [(Verified)GRISOFT LTD]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  33.       [Kaspersky Lab]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  35.     <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  37.       [(Verified)Microsoft Windows Publisher]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  39.       [Microsoft Corporation]

  40. ==================================
  41. 启动文件夹
  42. N/A

  43. ==================================
  44. 服务
  45. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  46.   
  47. [卡巴斯基反病毒6.0个人版 / AVP][Running/Auto Start]
  48.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r>
  49. [Human Interface Device Access / HidServ][Stopped/Disabled]
  50.   %SystemRoot%\System32\hidserv.dll>

  51. ==================================
  52. 驱动程序
  53. [360TimeProt / 360TimeProt][Running/Auto Start]
  54.   <\??\C:\WINDOWS\system32\drivers\360TimeProt.sys>
  55. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  56.   
  57. [AliIde / AliIde][Stopped/Boot Start]
  58.   <\SystemRoot\System32\DRIVERS\aliide.sys>
  59. [标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
  60.   <\SystemRoot\system32\DRIVERS\atapi.sys>
  61. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  62.   <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys>
  63. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  64.   
  65. [CmdIde / CmdIde][Running/Boot Start]
  66.   <\SystemRoot\System32\DRIVERS\cmdide.sys>
  67. [d346bus / d346bus][Running/Boot Start]
  68.   <\SystemRoot\system32\DRIVERS\d346bus.sys><>
  69. [d346prt / d346prt][Running/Boot Start]
  70.   <\SystemRoot\System32\Drivers\d346prt.sys><>
  71. [kl1 / kl1][Running/Boot Start]
  72.   <\SystemRoot\system32\drivers\kl1.sys>
  73. [klif / klif][Running/System Start]
  74.   <\??\C:\WINDOWS\system32\drivers\klif.sys>
  75. [MegaIDE / MegaIDE][Running/Boot Start]
  76.   <\SystemRoot\System32\DRIVERS\MegaIDE.sys>
  77. [nv / nv][Running/Manual Start]
  78.   
  79. [NVIDIA nForce MCP Networking Controller Driver / NVENET][Running/Manual Start]
  80.   
  81. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  82.   
  83. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  84.   
  85. [Secdrv / Secdrv][Stopped/Manual Start]
  86.   
  87. [TSP / TSP][Stopped/Manual Start]
  88.   <\??\C:\WINDOWS\system32\drivers\klif.sys>
  89. [ViaIde / ViaIde][Running/Boot Start]
  90.   <\SystemRoot\system32\DRIVERS\viaide.sys>

  91. ==================================
  92. 浏览器加载项
  93. [Adobe PDF Reader Link Helper]
  94.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
  95. [NTIECatcher Class]
  96.   {C56CB6B0-0D96-11D6-8C65-B2868B609932}
  97. [Web反病毒统计]
  98.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}
  99. [信息检索(&R)]
  100.   {92780B25-18CC-41C8-B9BE-3C9C571A8263}
  101. [Windows Live Photo Upload Control]
  102.   {7FC1B346-83E6-4774-8D20-1A6B09B0E737}
  103. [RealPlayer G2 Control]
  104.   {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}
  105. [Shockwave Flash Object]
  106.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  107. [Adobe PDF Reader Link Helper]
  108.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
  109. [NTIECatcher Class]
  110.   {C56CB6B0-0D96-11D6-8C65-B2868B609932}
  111. [使用影音传送带下载]
  112.   
  113. [使用影音传送带下载全部链接]
  114.   
  115. [导出到 Microsoft Office Excel(&X)]
  116.   

  117. ==================================
  118. 正在运行的进程
  119. [PID: 424 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  120. [PID: 720 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  121. [PID: 744 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  122.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.2.621]
  123.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  124.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  125.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  126. [PID: 792 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  127. [PID: 804 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  128. [PID: 956 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  129. [PID: 1036 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  130. [PID: 1156 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  131. [PID: 1208 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  132. [PID: 1368 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  133. [PID: 1408 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  134.     [C:\WINDOWS\system32\hpzsnt09.dll]  [HP, 2.236.4.0]
  135.     [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
  136.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
  137. [PID: 1696 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  138.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  139.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  140.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
  141.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  142.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  143.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\ShellEx.dll]  [Kaspersky Lab, 6.0.2.621]
  144.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll]  [GRISOFT s.r.o., 7, 5, 1, 36]
  145.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  146. [PID: 356 / Administrator][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe]  [GRISOFT s.r.o., 7, 5, 1, 43]
  147.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll]  [GRISOFT s.r.o., 4, 2, 0, 19]
  148.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  149.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  150. [PID: 408 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  151.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  152. [PID: 164 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  153. [PID: 2320 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.654\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  154.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  155.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  156.     [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.654\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  157. [PID: 2696 / Administrator][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  158.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  159.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  160. [PID: 2756 / Administrator][C:\Program Files\Maxthon2\Maxthon.exe]  [Maxthon International ltd., 2, 0, 2, 615]
  161.     [C:\Program Files\Maxthon2\mxpp.dll]  [Maxthon, 1, 0, 0, 50]
  162.     [C:\Program Files\Maxthon2\MxSk.dll]  [Maxthon, 1, 0, 0, 119]
  163.     [C:\Program Files\Maxthon2\MxProxy2.dll]  [, 1, 0, 0, 3115]
  164.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  165.     [C:\Program Files\Maxthon2\MxFav.dll]  [Maxthon, 1, 0, 0, 186]
  166.     [C:\Program Files\Maxthon2\maxzlib.dll]  [, 1.2.3]
  167.     [C:\Program Files\Maxthon2\mxtool.dll]  [, 1, 0, 0, 1]
  168.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  169.     [C:\Program Files\Maxthon2\mxfeedU.dll]  [, 1, 0, 45, 45]
  170.     [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
  171.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
  172.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
  173.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
  174.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
  175.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
  176.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.2.621]
  177.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
  178.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.2.621]
  179.     [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
  180.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  181.     [C:\WINDOWS\system32\Macromed\Common\SwSupport.dll]  [Adobe Systems, Inc., 10.2r22]

  182. ==================================
  183. 文件关联
  184. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  185. .EXE  OK. ["%1" %*]
  186. .COM  OK. ["%1" %*]
  187. .PIF  OK. ["%1" %*]
  188. .REG  OK. [regedit.exe "%1"]
  189. .BAT  OK. ["%1" %*]
  190. .SCR  OK. ["%1" /S]
  191. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  192. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  193. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  194. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  195. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  196. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  197. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  198. ==================================
  199. Winsock 提供者
  200. N/A

  201. ==================================
  202. Autorun.inf
  203. N/A

  204. ==================================
  205. HOSTS 文件
  206. 127.0.0.1       localhost

  207. ==================================
  208. 进程特权扫描
  209. 特殊特权被允许: SeLoadDriverPrivilege [PID = 2756, C:\PROGRAM FILES\MAXTHON2\MAXTHON.EXE]

  210. ==================================
  211. API HOOK
  212. RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  213. RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  214. RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  215. RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  216. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)

  217. ==================================
  218. 隐藏进程
  219. N/A

  220. ==================================
复制代码
shuipao
发表于 2007-9-24 22:52:39 | 显示全部楼层

回复 1楼 momowie 的帖子

安全模式下重新扫一个日志。
momowie
 楼主| 发表于 2007-9-25 16:01:30 | 显示全部楼层
得令重扫归来~~

  1. 2007-09-25,15:51:40
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <load><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  22.     <!AVG Anti-Spyware><"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [(Verified)GRISOFT LTD]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  24.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  25.     <Userinit><C:\WINDOWS\system32\UserInit.exe,>  [(Verified)Microsoft Windows Publisher]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  27.     <AppInit_DLLs><>  [N/A]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  31.     <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Publisher]
  32.     <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll>  [(Verified)GRISOFT LTD]
  33. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  34.     <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
  35.     <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
  36.     <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
  37.     <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
  39.     <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
  41.     <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
  43.     <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  45.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
  47.     <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
  49.     <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
  51.     <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
  53.     <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
  55.     <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  56. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
  57.     <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
  58. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
  59.     <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Publisher]
  60.     <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Publisher]
  61. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  62.     <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Publisher]
  63. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
  64.     <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
  65. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  66.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  67. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  68.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
  69. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  70.     <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
  71. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  72.     <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]
  73. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  74.     <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install>  [Microsoft Corporation]
  75. ==================================
  76. 启动文件夹
  77. N/A
  78. ==================================
  79. 服务
  80. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  81.   <C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><GRISOFT s.r.o.>
  82. [卡巴斯基反病毒6.0个人版 / AVP][Stopped/Auto Start]
  83.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  84. [Human Interface Device Access / HidServ][Stopped/Disabled]
  85.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  86. ==================================
  87. 驱动程序
  88. [360TimeProt / 360TimeProt][Stopped/Auto Start]
  89.   <\??\C:\WINDOWS\system32\drivers\360TimeProt.sys><N/A>
  90. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
  91.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  92. [AliIde / AliIde][Stopped/Boot Start]
  93.   <\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
  94. [标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
  95.   <\SystemRoot\system32\DRIVERS\atapi.sys><N/A>
  96. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Stopped/System Start]
  97.   <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
  98. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  99.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  100. [CmdIde / CmdIde][Running/Boot Start]
  101.   <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
  102. [d346bus / d346bus][Running/Boot Start]
  103.   <\SystemRoot\system32\DRIVERS\d346bus.sys><>
  104. [d346prt / d346prt][Running/Boot Start]
  105.   <\SystemRoot\System32\Drivers\d346prt.sys><>
  106. [kl1 / kl1][Stopped/Boot Start]
  107.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  108. [klif / klif][Stopped/System Start]
  109.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  110. [MegaIDE / MegaIDE][Running/Boot Start]
  111.   <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
  112. [nv / nv][Stopped/Manual Start]
  113.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  114. [NVIDIA nForce MCP Networking Controller Driver / NVENET][Stopped/Manual Start]
  115.   <system32\DRIVERS\NVENET.sys><NVIDIA Corporation>
  116. [Direct Parallel Link Driver / Ptilink][Stopped/Manual Start]
  117.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  118. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  119.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  120. [Secdrv / Secdrv][Stopped/Manual Start]
  121.   <system32\DRIVERS\secdrv.sys><N/A>
  122. [TCP/IP Protocol Driver / Tcpip][Stopped/System Start]
  123.   <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
  124. [TSP / TSP][Stopped/Manual Start]
  125.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  126. [ViaIde / ViaIde][Running/Boot Start]
  127.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  128. ==================================
  129. 浏览器加载项
  130. [Adobe PDF Reader Link Helper]
  131.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
  132. [NTIECatcher Class]
  133.   {C56CB6B0-0D96-11D6-8C65-B2868B609932} <C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll, Xi>
  134. [Web反病毒统计]
  135.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  136. [信息检索(&R)]
  137.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  138. [Windows Live Photo Upload Control]
  139.   {7FC1B346-83E6-4774-8D20-1A6B09B0E737} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
  140. [RealPlayer G2 Control]
  141.   {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
  142. [Shockwave Flash Object]
  143.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
  144. [Adobe PDF Reader Link Helper]
  145.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
  146. [NTIECatcher Class]
  147.   {C56CB6B0-0D96-11D6-8C65-B2868B609932} <C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll, Xi>
  148. [使用影音传送带下载]
  149.   <C:\Program Files\Xi\NetTransport 2\NTAddLink.html, N/A>
  150. [使用影音传送带下载全部链接]
  151.   <C:\Program Files\Xi\NetTransport 2\NTAddList.html, N/A>
  152. [导出到 Microsoft Office Excel(&X)]
  153.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  154. ==================================
  155. 正在运行的进程
  156. [PID: 152][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  157. [PID: 220][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  158. [PID: 244][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  159.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.2.621]
  160.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  161.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  162.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  163. [PID: 288][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  164.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  165. [PID: 300][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  166.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  167. [PID: 448][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  168.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  169. [PID: 496][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  170.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  171. [PID: 568][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe]  [GRISOFT s.r.o., 7, 5, 1, 22]
  172.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll]  [GRISOFT s.r.o., 4, 2, 0, 19]
  173. [PID: 600][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  174.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  175. [PID: 800][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  176.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  177.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  178.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  179.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  180.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll]  [GRISOFT s.r.o., 7, 5, 1, 36]
  181. [PID: 1104][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.155\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  182.     [C:\WINDOWS\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  183.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  184.     [C:\WINDOWS\system32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  185.     [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.155\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  186. ==================================
  187. 文件关联
  188. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  189. .EXE  OK. ["%1" %*]
  190. .COM  OK. ["%1" %*]
  191. .PIF  OK. ["%1" %*]
  192. .REG  OK. [regedit.exe "%1"]
  193. .BAT  OK. ["%1" %*]
  194. .SCR  OK. ["%1" /S]
  195. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  196. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  197. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  198. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  199. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  200. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  201. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  202. ==================================
  203. Winsock 提供者
  204. N/A
  205. ==================================
  206. Autorun.inf
  207. N/A
  208. ==================================
  209. HOSTS 文件
  210. 127.0.0.1       localhost
  211. ==================================
  212. 进程特权扫描
  213. N/A
  214. ==================================
  215. API HOOK
  216. N/A
  217. ==================================
  218. 隐藏进程
  219. N/A
  220. ==================================
复制代码
shuipao
发表于 2007-9-25 16:20:22 | 显示全部楼层

回复 3楼 momowie 的帖子

日志是正常的,现在咔吧报毒的路径是什么?那个进程占用cpu使用率大?
heqibao
发表于 2007-9-26 13:56:28 | 显示全部楼层

路过 看不懂

momowie
 楼主| 发表于 2007-9-26 22:26:50 | 显示全部楼层
今天出现的是C:\WINDOWS\sys36.exe(以前的sys数字.exe还会生成C:\WINDOWS\system32\26D744E2.EXE并修改注册表,今天这个似乎没有),具体占cpu没注意,因为之后ie马上出现explorer错误要关闭,我用icesword关闭进程后用killbox杀了,此后CPU比较正常,没发现什么异常进程。。。
头痛ing~~
shuipao
发表于 2007-9-27 13:00:05 | 显示全部楼层

回复 6楼 momowie 的帖子

你是说平时正常,用着用着就发现病毒了?是否局域网啊?不会是其他机器中招了吧。。
momowie
 楼主| 发表于 2007-9-28 06:02:04 | 显示全部楼层
报告,并没有局域网~~
我暂时就这么混着吧,sigh
momowie
 楼主| 发表于 2007-10-4 18:14:04 | 显示全部楼层
今天又来鸟,c:\windows\sys70.exe,生成C:\WINDOWS\system32\26D744E2.EXE修改注册表生成machine\controlset001\sevices\DE0D55FE\imagepath,头痛ing
njdzhan
发表于 2007-10-5 00:15:01 | 显示全部楼层
8位随机数又出新变种?!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-3-19 14:38 , Processed in 0.126258 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表