瑞星卡卡安全论坛
体会孤独 - 2006-4-28 9:27:00
C:\winnt\TEMP\a4bxosco.dll 这个病毒不停的出现,瑞星提示重启后杀,可重启后仍然在,真是头疼,请哪位帮助下我修复电脑啊!
这是我的hijackthis扫描日志:
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 9:26:09, 日期 2006-04-28
操作系统: Windows 2000 SP2 (WinNT 5.00.2195)
浏览器: Internet Explorer v5.00 SP2 (5.00.2920.0000)
当前运行的进程:
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll (file missing)
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: 安铁诺防毒软件-EXPLORER插件 - {9008B267-DBC2-475C-924A-9D93AFABB049} - C:\Program Files\sanlen\AntiUnknown\SNAURIN.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINNT\DOWNLO~1\cnshook.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - IE工具栏增项: 山丽网安 - {87E0B153-04FA-11D1-B7DA-10A0C90348D6} - C:\Program Files\sanlen\AntiUnknown\snashell.dll (file missing)
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINNT\DOWNLO~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [SNFRSSLV] C:\Program Files\sanlen\AntiUnknown\SNFRSSLV.exe
O4 - 启动项HKLM\\Run: [NTdhcp] C:\winnt\System32\NTdhcp.exe
O4 - 启动项HKLM\\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ScanRegistry] C:\Program Files\Common Files\update\update.exe
O4 - HKCU\..\Run: [NIW] C:\winnt\NIW.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\Program Files\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\Program Files\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\Program Files\Tencent\qq\SendMMS.htm
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS] 网络实名
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (趋势科技在线扫毒程序) - http://www.trendmicro.com.cn/housecall/xscan53.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/spyzero.cab
O16 - DPF: {ACFE8232-03C5-4AEC-AF5E-42B806724096} (KSHScan Control) - http://scan.kingsoft.com/scan/fangyi/KAllScan.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{D349E4F7-6112-4E3D-A39E-4C2821CFFBE3}: NameServer = 85.255.116.37,85.255.112.184
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
O23 - NT 服务: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\winnt\autoc.exe
O23 - NT 服务: NT LM Security Support Provide (NtlmSspp) - Unknown owner - C:\winnt\lsasss.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\Ravmond.exe
不言放弃 - 2006-4-28 9:30:00
【回复“体会孤独”的帖子】
HIJACKTHIS日志有很大问题
先说说病毒名称吧
体会孤独 - 2006-4-28 12:12:00
首先谢谢版主帮我解决问题!
病毒名称:Rootkit.Vanti.gen
不停的弹出杀毒窗口,就是杀不掉,真是头痛!!!
体会孤独 - 2006-4-28 13:05:00
不言放弃:
我还在在线等你啊。。。。为什么还没看我的贴子呢?
不言放弃 - 2006-4-28 13:06:00
【回复“体会孤独”的帖子】
我来了
感觉就是rootkit
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载System Repair Engineer 2.0.12.350
导出全部日志
体会孤独 - 2006-4-28 13:36:00
我用system repair engineer重新扫描的报告如下:
2006-04-28,13:31:03
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows 2000 Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ScanRegistry><C:\Program Files\Common Files\update\update.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<NIW><C:\winnt\NIW.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CnsMin><; Rundll32.exe C:\WINNT\DOWNLO~1\CnsMin.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<internat.exe><internat.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><; mobsync.exe /logon>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SNFRSSLV><C:\Program Files\sanlen\AntiUnknown\SNFRSSLV.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NTdhcp><C:\winnt\System32\NTdhcp.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"d:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<helper.dll><; C:\WINNT\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<iDuba Personal FireWall><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Kavrun><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<YahooC:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll4628843><regsvr32 /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<YahooC:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll4653656><regsvr32 /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<YahooC:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll4660187><regsvr32 /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<YahooC:\PROGRA~1\Yahoo!\ASSIST~1\yalliveex.dll4696015><regsvr32 /s C:\PROGRA~1\Yahoo!\ASSIST~1\yalliveex.dll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<WinAutoUp><C:\WINNT\AutoUp.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\winnt\System32\Userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
服务
[Logical Disk Manager Administrative Service / dmadmin]
<C:\winnt\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Gray_Pigeon_Server / GrayPigeonServer]
<C:\winnt\autoc.exe><N/A>
[NT LM Security Support Provide / NtlmSspp]
<C:\winnt\lsasss.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"d:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"d:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Universal Disk Manager / Universal Disk Manager]
<><N/A>
==================================
体会孤独 - 2006-4-28 13:38:00
一次发不下,再接上面的:
浏览器加载项
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[安铁诺防毒软件-EXPLORER插件]
{9008B267-DBC2-475C-924A-9D93AFABB049} <C:\Program Files\sanlen\AntiUnknown\SNAURIN.dll, N/A>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[CnsHook Class]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINNT\DOWNLO~1\cnshook.dll, 北京三七二一科技有限公司>
[Yahoo 1G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[寻宝乐趣多]
{59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[山丽网安]
{87E0B153-04FA-11D1-B7DA-10A0C90348D6} <C:\Program Files\sanlen\AntiUnknown\snashell.dll, N/A>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[V3ProX Control]
{5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} <C:\WINNT\DOWNLO~1\CONFLICT.1\v3prox.ocx, Ahnlab, Inc.>
[趋势科技在线扫毒程序]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\WINNT\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[SysMonOCX Control]
{9BDBC41E-C335-4263-83C0-ECE78EE28A33} <C:\WINNT\DOWNLO~1\SYSMON~1.OCX, ahnlab>
[KSHScan Control]
{ACFE8232-03C5-4AEC-AF5E-42B806724096} <C:\WINNT\System32\kingsoft\ONLINE~1\KSHScan.ocx, kingsoft>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\winnt\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
<E:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
<E:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
<E:\Program Files\Tencent\qq\SendMMS.htm, N/A>
[雅虎搜索]
<res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/246, N/A>
==================================
体会孤独 - 2006-4-28 13:41:00
接上面的:
==================================
正在运行的进程
[PID: 176][\??\C:\winnt\system32\csrss.exe] <Microsoft Corporation><5.00.2195.2581>
[C:\winnt\TEMP\a4bxosco.dll] <N/A><N/A>
[PID: 172][\??\C:\winnt\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.2953>
[PID: 224][C:\winnt\system32\services.exe] <Microsoft Corporation><5.00.2195.2780>
[C:\winnt\system32\dmserver.dll] <VERITAS Software Corp.><2195.2778.297.3>
[PID: 236][C:\winnt\system32\lsass.exe] <Microsoft Corporation><5.00.2195.2964>
[PID: 408][C:\winnt\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 432][d:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 448][d:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
[d:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[d:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[d:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[d:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[d:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[d:\Program Files\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[d:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[d:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[d:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[d:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[d:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[d:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[d:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[d:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[d:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[d:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[d:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
[d:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[d:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[d:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[d:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[d:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[d:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[d:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[d:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\winnt\TEMP\a4bxosco.dll] <N/A><N/A>
[d:\Program Files\Rising\Rav\RsStore.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[d:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 484][C:\winnt\system32\spoolsv.exe] <Microsoft Corporation><5.00.2161.1>
[PID: 524][C:\WINNT\System32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 588][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><5.00.2920.0000>
[C:\winnt\TEMP\a4bxosco.dll] <N/A><N/A>
[PID: 616][d:\MICROS~1\MSSQL\binn\sqlservr.exe] <Microsoft Corporation><2000.080.0194.00>
[PID: 708][C:\winnt\system32\regsvc.exe] <Microsoft Corporation><5.00.2195.2104>
[PID: 724][C:\winnt\system32\MSTask.exe] <Microsoft Corporation><4.71.2195.1>
[PID: 732][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><5.00.2920.0000>
[PID: 796][d:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[d:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 848][C:\winnt\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0029>
体会孤独 - 2006-4-28 13:42:00
好长啊!还有:
[PID: 1220][C:\winnt\System32\Rundll32.exe] <Microsoft Corporation><5.00.2134.1>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[C:\WINNT\DOWNLO~1\CnsMinEx.dll] <国风因特软件(北京)有限公司><1, 0, 2, 8>
[PID: 1364][C:\winnt\System32\internat.exe] <Microsoft Corporation><5.00.2920.0000>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[PID: 1388][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3208>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[PID: 1400][C:\winnt\System32\NTdhcp.exe] <N/A><N/A>
[C:\winnt\TEMP\a4bxosco.dll] <N/A><N/A>
[PID: 1432][D:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[PID: 1456][D:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 17>
[D:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[D:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[D:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[C:\winnt\TEMP\a4bxosco.dll] <N/A><N/A>
[PID: 1712][D:\Program Files\Rising\Rav\RsAgent.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[D:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 1704][C:\WINNT\msagent\AgentSvr.exe] <Microsoft Corporation><2.00.0.3422>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[PID: 1736][C:\winnt\System32\control.exe] <Microsoft Corporation><5.00.2134.1>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[PID: 1192][C:\winnt\System32\control.exe] <Microsoft Corporation><5.00.2134.1>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[PID: 1748][C:\winnt\System32\dllhost.exe] <Microsoft Corporation><5.00.2195.2815>
[PID: 1832][C:\WINNT\System32\msdtc.exe] <Microsoft Corporation><1999.9.3421.3>
[PID: 1140][C:\winnt\explorer.exe] <Microsoft Corporation><5.00.3315.2846>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[C:\WINNT\DOWNLO~1\cnshook.dll] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\winnt\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL] <N/A><N/A>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <><2, 0, 4, 1030>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\winnt\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll] <Yahoo! China><1, 0, 2, 1015>
[C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll] <Yahoo!><2, 1, 7, 1047>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <><1, 2, 7, 1006>
[C:\WINNT\System32\igfxpph.dll] <Intel Corporation><3,0,0,2082>
[C:\WINNT\System32\hccutils.DLL] <Intel Corporation><3,0,0,2082>
[PID: 2076][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe] < ><2, 0, 0, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <><2, 0, 4, 1030>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\Program Files\Yahoo!\Assistant\yNotifier.dll] <><1, 0, 0, 5>
[PID: 1980][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><5.00.2920.0000>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll] <Yahoo><1, 0, 1, 1000>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
[C:\WINNT\DOWNLO~1\CnsHint.dll] <3721><1, 0, 0, 6>
[C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll] <><2, 0, 4, 1030>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 0, 1006>
[C:\WINNT\DOWNLO~1\cnsplus.dll] <3721><1, 0, 0, 2>
[C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll] <Yahoo! China><1, 0, 2, 1015>
[C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll] <Yahoo.><1, 0, 2, 1002>
[C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll] <Yahoo!><2, 1, 7, 1047>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll] <Yahoo><1, 0, 1, 1004>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll] <Yahoo><1, 0, 1, 1000>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll] <><1, 0, 0, 9>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll] <Yahoo><1, 0, 0, 1>
[C:\WINNT\DOWNLO~1\cnshook.dll] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\winnt\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <><1, 2, 7, 1006>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\winnt\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll] < ><1, 0, 2, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll] <Yahoo><1, 0, 6, 1319>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll] <3721.com><2, 1, 1, 87>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll] <Yahoo><1, 0, 2, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yXPStyle.dll] <Yahoo><1, 0, 2, 1309>
[PID: 2028][E:\sreng2\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 0, 1013>
[C:\WINNT\DOWNLO~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 0>
==================================
文件关联
.TXT Error. [notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
轩辕小聪 - 2006-4-28 13:43:00
乖乖不得了,Rootkit合并灰鸽子、QQ大盗和其他木马,中毒颇深哪。
体会孤独 - 2006-4-28 13:44:00
终于发完了,我的电脑还有一个问题就是开机的时候提示boot.ini非法
如何修复还请版主指点!
轩辕小聪 - 2006-4-28 13:45:00
这个Rootkit插入进程还挺明显,得用IceSword了,甚至SSM。要我搞得累死,等不言的解决办法
不言放弃 - 2006-4-28 13:53:00
【回复“体会孤独”的帖子】
结束C:\winnt\System32\NTdhcp.exe进程
===============
开始--运行
输入regedit
确定
进入注册表
删除如下几项:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ScanRegistry><C:\Program Files\Common Files\update\update.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<NIW><C:\winnt\NIW.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NTdhcp><C:\winnt\System32\NTdhcp.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<iDuba Personal FireWall><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Kavrun><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<WinAutoUp><C:\WINNT\AutoUp.exe>
===============
开始--控制面板--性能和维护--管理工具--服务
禁用如下服务:
[Gray_Pigeon_Server / GrayPigeonServer]
[NT LM Security Support Provide / NtlmSspp]
[Universal Disk Manager / Universal Disk Manager]
开始--运行
输入regedit
确定
进入注册表
展开[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
找到后删除如下文件夹:
GrayPigeonServer文件夹
NtlmSspp文件夹
Universal Disk Manager文件
=================
删除
C:\Program Files\Common Files\update\
C:\Program Files\Common Files\COMM\
C:\winnt\NIW.exe
C:\winnt\System32\NTdhcp.exe
C:\WINNT\AutoUp.exe
C:\winnt\autoc.exe
C:\winnt\lsasss.exe
若能找到如下文件
同样删除之
C:\winnt\autoc.dll
C:\winnt\autockey.dll
C:\winnt\autoc_hook.dll
C:\winnt\lsasss.dll
C:\winnt\lsassskey.dll
C:\winnt\lsasss_hook.dll
=============
C:\winnt\System32\NTdhcp.exe是QQ大盗
会屏蔽瑞星杀软监控
请参考
http://forum.ikaka.com/topic.asp?board=28&artid=7866296
修改或重置一下瑞星的相关键值
=============
ttp://www.syssafety.com/
下载安装SSM(支持中文)
在SSM中添加规则
禁止C:\winnt\TEMP\a4bxosco.dll加载
并将SSM设置为“自动加载”
重启后删除
C:\winnt\TEMP\a4bxosco.dll
以及C:\winnt\TEMP\下的所有文件
提示:
SSM的使用方法参考http://forum.ikaka.com/topic.asp?board=28&artid=7990675
===============
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载后打开IceSword
在主界面点击左窗口中的“SSDT”按纽
删除对应的sys文件(切记不要误删)
提示:若不能判定某个sys文件是否是可疑文件
建议用百度或GOOGLE搜索一下该sys文件的详细资料
再决定是否删除
===============
【提示】
若正常模式下无法解决
建议进入安全模式下操作
【小常识】
若文件找不到或无法删除文件
建议进入安全模式下删除
打开我的电脑
在工具栏中点击--工具--文件夹选项--查看
勾选“显示所有文件及文件夹”
同时把“隐藏受保护的操作系统文件(推荐)”前的勾去掉
然后再进行查找一下
或利用KILLBOX来删除
KILLBOX下载:
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
或利用费尔木马强力清除助手来删除
费尔木马强力清除助手使用参考:
http://www.xfilt.com/tech/trojan-horse.htm
==============
建议按照上述步骤操作
轩辕小聪 - 2006-4-28 13:55:00
| 引用: |
【轩辕小聪的贴子】这个Rootkit插入进程还挺明显,得用IceSword了,甚至SSM。要我搞得累死,等不言的解决办法 ........................... |
呵呵,果然。
体会孤独 - 2006-4-28 13:58:00
晕。。。
大家都来帮我一下啊!!!不要只看看就走啊!!!
总有解决的办法吧。对你们的帮助我万分感谢!!!
轩辕小聪 - 2006-4-28 14:00:00
【回复“体会孤独”的帖子】
不言不是已经说了详细的方法了吗?照做就是了。
不言放弃 - 2006-4-28 14:03:00
| 引用: |
【轩辕小聪的贴子】 呵呵,果然。 ........................... |
两个QQ木马--都是盗QQ密码的
两个灰鸽子--个人认为
一个rootkit

拉风的春天 - 2006-4-28 14:08:00
晕倒~是我的话就看了也不会~
太恐怖了~
友好人士 - 2006-4-28 14:57:00
| 引用: |
【不言放弃的贴子】 两个QQ木马--都是盗QQ密码的
两个灰鸽子--个人认为
一个rootkit
........................... |
又一个百科全书!
体会孤独 - 2006-4-28 17:19:00
C:\winnt\System32\NTdhcp.exe进程
我在任务管理器里结束不了这个进程,请问还有没有什么办法结束?
轩辕小聪 - 2006-4-28 17:22:00
【回复“体会孤独”的帖子】
用IceSword结束此进程。
宝盒 - 2006-4-28 18:28:00
真是受益匪浅喔~呵呵。一看楼主就是3721的粉丝,哈……汗
safhsdyhfgdsagyg - 2006-4-28 18:49:00
我知道日志没问题是怎么回是,是因为病毒在攻击电脑时删除了那一段日志,建议把日志藏的难找一点。
米达麦亚已被占用 - 2006-4-28 19:54:00
同情啊,这么多病毒,楼主一定常看黄色网站
体会孤独 - 2006-4-29 9:53:00
今天我照版主的指导终于杀了那个可恶的病毒。
但是我重新查杀了我的电脑却发现了一个新的病毒,完全可以查杀,但是重启后却又出现了,这个病毒名称为:Trojan.Spy.Vidro.b
感染了两个文件:Explorer.EXE>>C:\winnt\Explorer.EXE csrss.exe>>\??\C:\winnt\system32\csrss.exe
这有什么办法解决吗?还有我的boot.ini文件损坏有什么办法可以修复吗?
hijathis扫描如下:
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 9:49:52, 日期 2006-04-29
操作系统: Windows 2000 SP2 (WinNT 5.00.2195)
浏览器: Internet Explorer v5.00 SP2 (5.00.2920.0000)
当前运行的进程:
C:\winnt\System32\smss.exe
C:\winnt\system32\csrss.exe
C:\winnt\system32\winlogon.exe
C:\winnt\system32\services.exe
C:\winnt\system32\lsass.exe
C:\winnt\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
d:\Program Files\Rising\Rav\Ravmond.exe
C:\winnt\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
d:\MICROS~1\MSSQL\binn\sqlservr.exe
C:\winnt\system32\regsvc.exe
C:\winnt\system32\MSTask.exe
C:\winnt\System32\WBEM\WinMgmt.exe
d:\Program Files\Rising\Rav\RavStub.exe
C:\winnt\Explorer.EXE
C:\winnt\System32\Rundll32.exe
C:\winnt\System32\internat.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\Rising\Rav\Rav.exe
D:\Program Files\Rising\Rav\RsAgent.exe
C:\WINNT\msagent\AgentSvr.exe
C:\winnt\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
E:\download\HijackThis V1[1].99.1 完全汉化版\HijackThis1991zww.exe
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: 安铁诺防毒软件-EXPLORER插件 - {9008B267-DBC2-475C-924A-9D93AFABB049} - C:\Program Files\sanlen\AntiUnknown\SNAURIN.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINNT\DOWNLO~1\cnshook.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [SNFRSSLV] C:\Program Files\sanlen\AntiUnknown\SNFRSSLV.exe
O4 - 启动项HKLM\\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [yassistse] ; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [YLive.exe] ; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\Program Files\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\Program Files\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\Program Files\Tencent\qq\SendMMS.htm
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/246
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS] 网络实名
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (趋势科技在线扫毒程序) - http://www.trendmicro.com.cn/housecall/xscan53.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/spyzero.cab
O16 - DPF: {ACFE8232-03C5-4AEC-AF5E-42B806724096} (KSHScan Control) - http://scan.kingsoft.com/scan/fangyi/KAllScan.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{D349E4F7-6112-4E3D-A39E-4C2821CFFBE3}: NameServer = 85.255.116.37,85.255.112.184
O20 - Winlogon Notify: System Safety Monitor - C:\winnt\SYSTEM32\SSMWinlogonEx.dll
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\Ravmond.exe
不言放弃 - 2006-4-29 9:57:00
【回复“体会孤独”的帖子】
日志并没有问题
病毒文件名称与路径?
boot.ini文件损坏
可以重新创建一个boot.ini
体会孤独 - 2006-4-29 10:02:00
上面我说了的啊:
病毒名称:Trojan.Spy.Vidro.b
病毒文件路径:C:\winnt\Explorer.EXE
C:\winnt\system32\csrss.exe
还请版主告诉我一下如何创建一个boot.ini
黑灯黑火 - 2006-4-29 10:05:00
呵呵,,不言的解释果然够祥细~~
不言放弃 - 2006-4-29 10:07:00
| 引用: |
【体会孤独的贴子】上面我说了的啊: 病毒名称:Trojan.Spy.Vidro.b 病毒文件路径:C:\winnt\Explorer.EXE C:\winnt\system32\csrss.exe 还请版主告诉我一下如何创建一个boot.ini ........................... |
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载System Repair Engineer 2.0.12.350
导出全部日志
体会孤独 - 2006-4-29 10:10:00
2006-04-29,10:08:32
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows 2000 Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<internat.exe><internat.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SNFRSSLV><C:\Program Files\sanlen\AntiUnknown\SNFRSSLV.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"d:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\winnt\System32\Userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
© 2000 - 2026 Rising Corp. Ltd.