咕咕咚咚 - 2007-4-25 18:08:00
昨天局域网里好几台机器出现情况:部分EXE文件体积变大,不能运行(点击后无反应)。经对比正常文件与染毒文件,发现HKM-softwore-Microsoft-windows-CurrentVersion-ShellServiceObjectDelayLoad下多了个DirectX-值为{DA1910DE-AA86-4ED0-874B-2924E38BAD99},winnt\system32下多D9DX.DLL和d3d8xof.dll,删除该键值并结束EXPLORER进程后删除system32下两个文件后觉得病毒应该清除干净了,但是现在的问题是很多EXE文件已经染毒无法清除,重启后无论哪个EXE文件一运行,键值和病毒文件都又出来了。
请问有人知道该怎么办吗?严重感谢。
孤独更可靠 - 2007-4-25 18:14:00
SRENG的官方下载地址:
http://www.kztechs.com/sreng/download.html
打不开的话,到我网盘
http://gudugengkekao.ys168.com
(其他工具-sreng2.zip 0.6MB )
先暂时关闭QQ、播放之类的东西,选第四选项-智能扫描-勾选上检查进程模块的数字签名-扫描后保存报告~把内容粘上来,一次粘不完分几次粘,中间不要修改..
咕咕咚咚 - 2007-4-25 18:16:00
日志太长,分两部分发
[CODE]
2007-04-25,18:01:20
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Advanced Server Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)Microsoft Windows 2000 Publisher]
<jiajiabx><E:\新建文件夹\jjsetup41\jjbxb\jiajiabx.exe> [加加工作组]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<High Definition Audio 属性页快捷方式><HDAShCut.exe> [(Verified)Microsoft Windows 2000 Publisher]
<Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
<NvCplDaemon><RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<nwiz><nwiz.exe /install> [NVIDIA Corporation]
<NvMediaCenter><RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
<ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe> [(Verified)Symantec Corporation]
<StatusClient><C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto> [Hewlett-Packard]
<TomcatStartup><C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe> [Hewlett-Packard]
<360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start> [奇虎网]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows 2000 Publisher]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{131AB311-16F1-F13B-1E43-11A24B51AFD1}><C:\WINNT\system32\gdipri.dll> []
<{D14FA1E2-123F-6358-1E32-D2455234FDE2}><C:\WINNT\system32\nospri.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<DirectX><C:\WINNT\system32\d3d8xof.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINNT\system32\NavLogon.dll> [(Verified)Symantec Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><(无)> [N/A]
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~4\Office\OSA9.EXE [Microsoft Corporation]><N>
==================================
服务
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINNT\system32\nvsvc32.exe><NVIDIA Corporation>
[Pml Driver HPZ12 / Pml Driver HPZ12][Stopped/Manual Start]
<C:\WINNT\system32\HPZipm12.exe><HP>
[SavRoam / SavRoam][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Stopped/Manual Start]
<C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
==================================
咕咕咚咚 - 2007-4-25 18:16:00
驱动程序
[C-Media High Definition Audio Interface / cmudax][Running/Manual Start]
<system32\drivers\cmudax.sys><C-Media Inc.>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[Microsoft 用于 High Definition Audio 服务的 UAA 功能驱动程序 / HdAudAddService][Stopped/Manual Start]
<system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[IEEE-1284.4 Driver HPZid412 / HPZid412][Running/Manual Start]
<system32\DRIVERS\HPZid412.sys><HP>
[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12][Running/Manual Start]
<system32\DRIVERS\HPZipr12.sys><HP>
[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12][Running/Manual Start]
<system32\DRIVERS\HPZius12.sys><HP>
[ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start]
<System32\DRIVERS\ASACPI.sys><>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070424.020\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070424.020\navex15.sys><Symantec Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\E:\新建文件夹\QQ2005\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[SAVRT / SAVRT][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[SPBBCDrv / SPBBCDrv][Stopped/Manual Start]
<\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[WINIO / WINIO][Stopped/Manual Start]
<\??\G:\winio.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[NDIS5 Miniport Driver for Marvell Yukon Ethernet Controller / yukonw2k][Running/Manual Start]
<System32\DRIVERS\yk50x86.sys><Marvell>
==================================
浏览器加载项
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\熊\新建文件夹\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} <C:\WINNT\DOWNLO~1\PowerPlr.ocx, 创智数码科技股份有限公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[WebThunder Class]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[使用Web迅雷下载]
<D:\熊\新建文件夹\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<D:\熊\新建文件夹\GetAllUrl.htm, N/A>
==================================
正在运行的进程
[PID: 180][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 212][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 208][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6970]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\NavLogon.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[PID: 1496][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\system32\gdipri.dll] [N/A, ]
[C:\WINNT\system32\nospri.dll] [N/A, ]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\d9dx.dll] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[D:\熊\新建文件夹\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\WINNT\system32\msadp32.acm] [Microsoft Corporation, 5.00.2134.1]
[PID: 1732][C:\WINNT\system32\RunDll32.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system\cmicnfg.cpl] [C-Media Corporation, 1, 0, 46, 4]
[C:\WINNT\System32\udaprop.dll] [C-Media Corporation, 1.0.2.3]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[PID: 1760][C:\Program Files\Common Files\Symantec Shared\ccApp.exe] [Symantec Corporation, 103.5.1.9]
[C:\WINNT\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Symantec Shared\ccL35.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.1.9]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 103.5.1.9]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 103.5.1.9]
[C:\WINNT\system32\SYMREDIR.DLL] [Symantec Corporation, 5.5.1.6]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Symantec AntiVirus\SavEmail.dll] [Symantec Corporation, 10.0.0.359]
[PID: 1840][C:\PROGRA~1\SYMANT~1\VPTray.exe] [Symantec Corporation, 10.0.0.359]
[C:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINNT\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] [Symantec Corporation, 9.5.0.44]
[C:\Program Files\Symantec AntiVirus\Cliscan.dll] [Symantec Corporation, 10.0.0.359]
[C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL] [Symantec Corporation, 10.0.0.359]
[C:\Program Files\Symantec AntiVirus\Cliproxy.dll] [Symantec Corporation, 10.0.0.359]
[PID: 1868][C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe] [Hewlett-Packard, 00.00.13]
[PID: 1896][C:\Program Files\360safe\safemon\360Tray.exe] [奇虎网, 3, 3, 0, 1004]
[C:\Program Files\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001]
[C:\Program Files\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 2, 0, 1001]
[C:\Program Files\360safe\AntiAdwa.dll] [360Safe.com, 3, 3, 0, 1004]
[PID: 1884][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[PID: 1996][E:\新建文件夹\jjsetup41\jjbxb\jiajiabx.exe] [加加工作组, 4, 1, 0, 43]
[PID: 2076][C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe] [N/A, ]
[C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\hotspot\jvm.dll] [N/A, ]
[C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\hpi.dll] [N/A, ]
[C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\verify.dll] [N/A, ]
[C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\java.dll] [N/A, ]
[C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\zip.dll] [N/A, ]
[C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\net.dll] [N/A, ]
[C:\WINNT\system32\d4channel.dll] [Hewlett-Packard, 02.07.00]
[PID: 800][D:\128U盘\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[D:\128U盘\sreng2\Plugins\NWMON.SRE] [Smallfrogs Studio, 1, 0, 0, 8]
[PID: 2748][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[D:\熊\新建文件夹\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0]
[C:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673]
[C:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\msadp32.acm] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\WINNT\system32\msratelc.dll] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\system32\PINTLGNT.IME] [Microsoft Corporation, 4.2.32]
[C:\WINNT\system32\winabc.ime] [Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\system32\JJBX.IME] [加加工作组, 4, 1, 0, 42]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
孤独更可靠 - 2007-4-25 18:25:00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{131AB311-16F1-F13B-1E43-11A24B51AFD1}><C:\WINNT\system32\gdipri.dll> []
<{D14FA1E2-123F-6358-1E32-D2455234FDE2}><C:\WINNT\system32\nospri.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<DirectX><C:\WINNT\system32\d3d8xof.dll> [Microsoft Corporation]
太专业了吧?冒充DX的?
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><(无)> [N/A]
你弄的屏保?
[WINIO / WINIO][Stopped/Manual Start]
<\??\G:\winio.sys><N/A>
....
[C:\WINNT\system32\gdipri.dll] [N/A, ]
[C:\WINNT\system32\nospri.dll] [N/A, ]
把你说感染EXE(不能运行)随便捡几个仍到Lyhan_1988@163.com
加密123
咕咕咚咚 - 2007-4-25 21:06:00
已经发邮件给你了,请帮忙看一下,谢谢了:)
孤独更可靠 - 2007-4-25 21:13:00
样本已收到..
由于有其他事情..
明天再分析拉
................
咕咕咚咚 - 2007-4-25 21:21:00
【回复“孤独更可靠”的帖子】
好的
星10000 - 2007-4-26 9:02:00
把 感染的exe 发来\
================
部分EXE文件体积变大,不能运行(点击后无反应)。经对比正常文件与染毒文件,==
========
你可试下自已修复exe
凝逸.修复感染EXE1.0
[凝逸.修复感染]
专针对文件头被病毒感染清理还原,病毒样本少,处理快!
自已提取样本,修复感染EXE
[扫描操作]
[病毒库]>>选择病毒样本>>单击"[扫描]"进行搜索清理
或把一个可疑的文件直接拉到窗口内检查清理.
[提取病毒样本1]:
分析病毒前一要确定,
2个文件一定是相同文件()
一个是末感染的文件,一个是源已被感染文件!
如:qq.exe感染了,你到qq网站下一个相同版本的qq.exe
[提取病毒样本2]:
提取病毒前一要确定,
感染相同的病毒的2个exe文件,2个文件要不相同的!
如:QQ.exe 与 QQexternal.exe ,2个感染了病毒
这个好寻找到文件
20070423_503165656_Worm.Viking_.xge
提取者与病毒名不用中文为好,这样在英文系统下也能读取!
病毒样本"*.xge",可发给别人共享
=====================
[凝逸反毒5.5]
功能:
[扫描病毒]
功能:清除灰鸽子,威金,熊猫,金猪,蓝天草地,木马,终结者,U盘病毒等
[凝逸.修复EXE引擎]
功能:修复威金,熊猫,金猪,Logo1_.exe,U盘病毒(各种未知变种)等所感染的EXE
[清除网页病毒]
功能:清除网页病毒代码与病毒网址
[凝逸反毒-自己批量加入病毒样本]
http://hi.baidu.com/503165656/blog/item/04336f08458b33940a7b82a5.html
凝逸实验室
作者:凝逸
凝逸反毒
主页:[hi.baidu.com/503165656]
软件:[503165656.ys168.com]
客服QQ:503165656
TM群:24874517
=============
孤独更可靠 - 2007-4-26 9:36:00
早上测试了
无法运行
跟你说的情况差不多
估计想模仿熊猫,捆绑文件,可能是其他原因,被感染的文件无法运行(难道是有意的?)
日志\文件\注册表等均无异常
才给2个样本,不好测试(另一个没问题,可以正常运行)
好像这个病毒是针对Nt server系统的
没有主体病毒,不好下结论
林达asd - 2007-4-26 9:58:00
先支持一下...
© 2000 - 2026 Rising Corp. Ltd.