xiaoshzi - 2007-4-19 14:56:00
这台机器昨天做了2遍系统,安装了瑞星2007,升级到最新病毒库,利用瑞星防火墙打了所有的补丁。今天早上病毒就又出来了,请帮助我解决这个问题。以下是日志
[CODE]
2007-04-19,13:53:54
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<jiajiasr><C:\Program Files\jj4\jiajiasr.exe> [加加工作组]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<C:\DOCUME~1\user\LOCALS~1\Temp\ttp.exe><C:\DOCUME~1\user\LOCALS~1\Temp\ttp.exe> [N/A]
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe> [CNNIC]
<HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation]
<IgfxTray><; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><"\Program Files\Logonui\Royale.exe"> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Corporation]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\System72.sys> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Corporation]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Corporation]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\System32\logon.scr> [(Verified)Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
[0C8E0860 / 0C8E0860][Stopped/Auto Start]
<C:\WINDOWS\system32\0C8E0860.EXE -0C8E0860><Microsoft Corporation>
[6A168E6E / 6A168E6E][Stopped/Auto Start]
<C:\WINDOWS\system32\6A168E6E.EXE -service><Microsoft Corporation>
[D5A52D1A / D5A52D1A][Stopped/Auto Start]
<C:\WINDOWS\system32\D5A52D1A.EXE -a><Microsoft Corporation>
[E2023519 / E2023519][Stopped/Auto Start]
<C:\WINDOWS\system32\E2023519.EXE -k><Microsoft Corporation>
[E5A3DD04 / E5A3DD04][Stopped/Auto Start]
<C:\WINDOWS\system32\E5A3DD04.EXE -p><Microsoft Corporation>
[error monitor / EmonSrv][Stopped/Auto Start]
<C:\WINDOWS\system32\bc99.exe><N/A>
[Gentad / Gentad][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\Struts.dll><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[kkdj3sdf3 / kkdj3sdf3][Stopped/Auto Start]
<C:\WINDOWS\system32\kkdj3sdf3.exe -j><Microsoft Corporation>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Stopped/Auto Start]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Stopped/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Windows upvu RunThem / upvu][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\mhqm\wuaw.dll>< >
陕西兵马俑 - 2007-4-19 15:02:00
如果你是全格装的话,装好后就要装杀毒软件并升级,然后再装其它的什么软件。应该不会出现这么多的毒
xiaoshzi - 2007-4-19 15:05:00
==================================
驱动程序
[acpidisk / acpidisk][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[AliIde / AliIde][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[Rising TDI Base Driver / BaseTDI][Stopped/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[cdnprot / cdnprot][Stopped/Boot Start]
<\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[ialm / ialm][Stopped/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[jahfaief / jahfaief][Stopped/Boot Start]
<\SystemRoot\system32\drivers\jahfaief.sys><N/A>
[MegaIDE / MegaIDE][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Stopped/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
==================================
浏览器加载项
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[IeHelper Class]
{0D42E1BD-09DD-4873-A826-9C7E793EB7B6} <C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DSIeHelper.dll, Thunder Networking Technologies,LTD>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[]
{5F551A91-F949-49C6-812F-1783D14F8D01} <C:\WINDOWS\system32\baisrc.dll, N/A>
[ExtentIE Class]
{66C2C482-D4EE-42A5-AEF7-0B124F278D47} <C:\WINDOWS\system32\7bc9.dll, TODO: <公司名>>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[TBSB04805 Class]
{9674F35D-1337-4F6E-820E-BAC4C2380580} <C:\PROGRA~1\工具栏~1\tbu01885\tttt.dll, N/A>
[]
{A44F0E9A-0DA2-4C48-89A9-43055EF16323} <C:\WINDOWS\system32\jbgatxjqnxweg.dll, N/A>
[]
{C8AF24A6-3564-4F64-84A3-AA80C88EDD8A} <C:\WINDOWS\system32\vrdztayedgcky.dll, N/A>
[AlxTB BHO Class]
{F1FABE79-25FC-46de-8C5A-2C6DB9D64333} <C:\WINDOWS\system32\AlxTB1.dll, Alexa Internet>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[工具栏(T)]
{42A2F05F-E171-4CEF-852F-02475F698C24} <C:\Program Files\工具栏(T)\tbu01885\tttt.dll, N/A>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[工具栏(T)]
{42A2F05F-E171-4CEF-852F-02475F698C24} <C:\Program Files\工具栏(T)\tbu01885\tttt.dll, N/A>
[Alexa]
{3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} <C:\WINDOWS\system32\SHDOCVW.DLL, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[IeHelper Class]
{0D42E1BD-09DD-4873-A826-9C7E793EB7B6} <C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DSIeHelper.dll, Thunder Networking Technologies,LTD>
[Menu Class]
{27D784D7-9217-4227-B43B-E06E4781E0CB} <C:\WINDOWS\system32\AlxTB1.dll, Alexa Internet>
[Alexa]
{3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} <C:\WINDOWS\system32\SHDOCVW.DLL, Microsoft Corporation>
[工具栏(T)]
{42A2F05F-E171-4CEF-852F-02475F698C24} <C:\Program Files\工具栏(T)\tbu01885\tttt.dll, N/A>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[]
{5F551A91-F949-49C6-812F-1783D14F8D01} <C:\WINDOWS\system32\baisrc.dll, N/A>
[ExtentIE Class]
{66C2C482-D4EE-42A5-AEF7-0B124F278D47} <C:\WINDOWS\system32\7bc9.dll, TODO: <公司名>>
[BrowserProxy4 Class]
{69A72A8A-84ED-4A75-8CE7-263DBEF3E5D3} <C:\WINDOWS\system32\AlxTB1.dll, Alexa Internet>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[TBSB04805 Class]
{9674F35D-1337-4F6E-820E-BAC4C2380580} <C:\PROGRA~1\工具栏~1\tbu01885\tttt.dll, N/A>
[]
{A44F0E9A-0DA2-4C48-89A9-43055EF16323} <C:\WINDOWS\system32\jbgatxjqnxweg.dll, N/A>
xiaoshzi - 2007-4-19 15:07:00
我就是在断网,格式化分区,安装完杀毒软件,升级到最新病毒库,安装完系统补丁后感染的病毒
勇闯猪罗纪 - 2007-4-19 15:08:00
你重装就要全格 不然重装一点意义也没有
C D E F G 全格了 我就不信还有毒 我跟你姓
我是流浪猪 - 2007-4-19 15:09:00
| 引用: |
【勇闯猪罗纪的贴子】你重装就要全格 不然重装一点意义也没有 C D E F G 全格了 我就不信还有毒 我跟你姓 ……………… |
xiaoshzi - 2007-4-19 16:03:00
勇闯猪罗纪 你在玩吗? 那我还不如换个电脑了
独孤剑客 - 2007-4-19 16:23:00
[0C8E0860 / 0C8E0860][Stopped/Auto Start]
<C:\WINDOWS\system32\0C8E0860.EXE -0C8E0860><Microsoft Corporation>
[6A168E6E / 6A168E6E][Stopped/Auto Start]
<C:\WINDOWS\system32\6A168E6E.EXE -service><Microsoft Corporation>
[D5A52D1A / D5A52D1A][Stopped/Auto Start]
<C:\WINDOWS\system32\D5A52D1A.EXE -a><Microsoft Corporation>
[E2023519 / E2023519][Stopped/Auto Start]
<C:\WINDOWS\system32\E2023519.EXE -k><Microsoft Corporation>
[E5A3DD04 / E5A3DD04][Stopped/Auto Start]
<C:\WINDOWS\system32\E5A3DD04.EXE -p><Microsoft Corporation>
[error monitor / EmonSrv][Stopped/Auto Start]
<C:\WINDOWS\system32\bc99.exe><N/A>
[Gentad / Gentad][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\Struts.dll><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\DOCUME~1\user\LOCALS~1\Temp\ttp.exe><C:\DOCUME~1\user\LOCALS~1\Temp\ttp.exe> [N/A]
<UIHost><"\Program Files\Logonui\Royale.exe"> [Microsoft Corporation]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\System72.sys> [N/A]
[kkdj3sdf3 / kkdj3sdf3][Stopped/Auto Start]
<C:\WINDOWS\system32\kkdj3sdf3.exe -j><Microsoft Corporation>
[Windows upvu RunThem / upvu][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\mhqm\wuaw.dll>< >
[jahfaief / jahfaief][Stopped/Boot Start]
<\SystemRoot\system32\drivers\jahfaief.sys><N/A>
© 2000 - 2026 Rising Corp. Ltd.