| 引用: |
| 【ymmymm的贴子】想玩极品飞车10,搜个修改器,结果搜到一个网站有下,地址为 hxxp://www.baobei555.com/soft/3621.htm(病毒十分厉害,菜鸟请谨慎实验) 一打开网站瑞星就报有毒,但是要手动删除~我没理准备下好了再去手动删掉,把下面的软件下载下来.图标是个解压缩图标.我也没仔细看就点了,然后解出一个文件夹,文件夹一打开病毒发作 症状: 1:修改主版时间让瑞星残废(变成查毒版本不能杀毒) 2:植入流氓软件,打开NNN个流氓网站,关都来不及(超级兔子,瑞星网络助手都有装还是不行) 3:自动生成NNN个木马软件开始疯狂连接网络(装了瑞星防火墙,没有作用) 1分钟后机器瘫痪 重起进安全模式 系统损坏说缺少什么文件 机器牛卡 断网重装系统,第一时间装好杀软,问题照旧 因为病毒是下在D盘的,我把D盘格了重装系统,问题照旧 挂上外盘准备转移资料,但是系统已经全面感染,此时杀毒软件一个毒都杀不出了,我只要一打开一个盘符,病毒就自动植入,所以资料也拯救不了~ 现在是一点办法都没了~`在线等达人赐教了 2007-04-27,01:26:26 System Repair Engineer 2.4.12.806 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher] <bgswitch><C:\WINDOWS\system32\bgswitch.exe> [] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <load><> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher] <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher] <RavTask><"d:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.] <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation] <nwiz><nwiz.exe /install> [] <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation] <RTHDCPL><RTHDCPL.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <Alcmtr><ALCMTR.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <RfwMain><"d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <shell><Explorer.exe> [(Verified)Microsoft Windows XP Publisher] <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <AppInit_DLLs><> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.] ================================== 启动文件夹 N/A ================================== 服务 [Human Interface Device Access / HidServ][Stopped/Disabled] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A> [NVIDIA Display Driver Service / NVSvc][Stopped/Auto Start] <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation> [Rising Proxy Service / RfwProxySrv][Stopped/Manual Start] <d:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.> [Rising Personal Firewall Service / RfwService][Running/Auto Start] <d:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"d:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.> [Rising RealTime Monitor / RsRavMon][Running/Auto Start] <"D:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.> [Windows Accounts Driver / WindowsConnections][Stopped/Auto Start] <C:\WINDOWS\system32\222.exe><N/A> [Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start] <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation> ================================== 驱动程序 [Rising TDI Base Driver / BaseTDI][Running/Auto Start] <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.> [Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Running/Manual Start] <system32\DRIVERS\e1e5132.sys><Intel Corporation> [ExpScaner / ExpScaner][Running/Auto Start] <\??\D:\PROGRAM FILES\RISING\RAV\ExpScan.sys><> [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider> [HookCont / HookCont][Running/Auto Start] <\??\D:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising> [HookReg / HookReg][Running/Auto Start] <\??\D:\PROGRAM FILES\RISING\RAV\HookReg.sys><> [HookSys / HookSys][Running/Auto Start] <\??\D:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising> [HookUrl / HookUrl][Running/Auto Start] <\??\d:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.> [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.> [ITEATAPI_Service_Install / iteatapi][Running/Boot Start] <\SystemRoot\system32\DRIVERS\iteatapi.sys><Integrated Technology Express, Inc.> [ITERAID_Service_Install / iteraid][Running/Boot Start] <\SystemRoot\system32\DRIVERS\iteraid.sys><Integrated Technology Express, Inc.> [MEMSCAN / MEMSCAN][Running/Auto Start] <\??\D:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司> [mProcRs / mProcRs][Running/Auto Start] <\??\d:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.> [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start] <system32\DRIVERS\ASACPI.sys><> [nv / nv][Running/Manual Start] <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.> [RsFwDrv / RsFwDrv][Running/Auto Start] <\??\d:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.> [RSPPSYS / RSPPSYS][Running/Auto Start] <\??\D:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising> [Secdrv / Secdrv][Stopped/Manual Start] <system32\DRIVERS\secdrv.sys><N/A> ……………… |