瑞星卡卡安全论坛
wuchuanwei - 2007-6-4 21:06:00
病毒特征:将硬盘分区内文件全部隐藏,(从文件夹属性中显示隐藏文件属性后还是看不见分区内的文件),但如果直接敲打路径还是可以进入文件夹的,(比如的D:/BAK,就可以看见bak文件夹里面内容,证明分区内文件并未丢失)
杀毒软件会不定时在临时文件夹中杀出cs.jpg(还有一些其他.jpg格式,具体我记不清除了)等病毒,并删除之,但重启电脑速度爆慢,资源被耗尽,安全模式下则一切正常。
用瑞星或国外正版杀毒软件升级后在安全模式下杀毒并无病毒,用360安全助手等恶意软件清理系统也没有什么收获。
这个问题简直太棘手了,希望有哪位高手为我指点一下!谢谢!
水晶玻璃球里的鱼 - 2007-6-4 21:14:00
帮你支持下,想知道解决办法,积累知识.
█ikaka█ - 2007-6-4 21:19:00
太简单,有没有难一点的问题呀!
wuchuanwei - 2007-6-4 21:21:00
很简单?请楼上的兄弟给个解决办法,我被困扰好几天了,谢谢啊!
水晶玻璃球里的鱼 - 2007-6-4 21:27:00
简单??
怎么解决?
随便叫吧 - 2007-6-4 21:36:00
同样问题,一样期待
帮你,帮我自己顶一下
spiritfire - 2007-6-4 21:43:00
http://download.kztechs.com/files/sreng2.zip
上面这个链接下载SREng,
关闭不必要的程序,运行SREng.exe,“智能扫描”-“保存报告”,
分段贴上来!
rj600700 - 2007-6-4 21:49:00
我也在等着看结果哦!!!
loveperday - 2007-6-4 22:35:00
全部隐藏?批量修改文件属性?晕~
wuchuanwei - 2007-6-4 23:41:00
办公室电脑,明天上班帖个日志上来。
wuchuanwei - 2007-6-5 8:39:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Arp保护神><D:\桌面文件1\arp430.exe> []
<WinnetManager><C:\WINDOWS\system32\WinnetManager.exe> []
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
wuchuanwei - 2007-6-5 8:39:00
启动文件夹
[ip]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\ip.bat --> [N/A]><N>
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[arp8023 / arp8023][Stopped/Manual Start]
<\SystemRoot\system32\drivers\arp8023.sys><N/A>
[ati2mtag / ati2mtag][Stopped/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[BaseTDI / BaseTDI][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
[HookReg / HookReg][Stopped/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\E:\软件系列\Tencent\QQ\npkcrypt.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
wuchuanwei - 2007-6-5 8:39:00
浏览器加载项
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[WangWangObj Class]
{6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <C:\Program Files\淘宝网\淘宝旺旺\WangWangX4.dll, 阿里软件(中国)有限公司>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[使用迅雷下载]
<E:\迅雷\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
<E:\迅雷\Program\getallurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
wuchuanwei - 2007-6-5 8:40:00
正在运行的进程
[PID: 460][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 320][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4396]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4396]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[PID: 508][D:\桌面文件1\arp430.exe] [N/A, ]
[E:\temp\E_4\krnln.fnr] [, 1, 0, 0, 1]
[E:\temp\E_4\iext5.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\sock.fne] [N/A, ]
[E:\temp\E_4\eAPI.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\internet.fne] [, 1, 0, 0, 1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 724][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 124][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 812][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 888][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1420][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2168][C:\Documents and Settings\Administrator\桌面\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
wuchuanwei - 2007-6-5 8:40:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
wuchuanwei - 2007-6-5 8:41:00
以上是我办公室电脑的日志,请高手诊断!
孤独更可靠 - 2007-6-5 8:44:00
本人菜鸟
不过还是没发现问题..
天月来了 - 2007-6-5 10:30:00
估计扫错电脑了吧???????????
jinny001 - 2007-6-5 10:39:00
[E:\temp\E_4\krnln.fnr] [, 1, 0, 0, 1]
[E:\temp\E_4\iext5.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\sock.fne] [N/A, ]
[E:\temp\E_4\eAPI.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\internet.fne] [, 1, 0, 0, 1]
这些也在进程里?是不是有问题呀~~
还有就是把这个硬盘挂到别的电脑上,显示一下隐藏文件,查杀一下病毒看看.
jinny001 - 2007-6-5 10:40:00
[E:\temp\E_4\krnln.fnr] [, 1, 0, 0, 1]
[E:\temp\E_4\iext5.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\sock.fne] [N/A, ]
[E:\temp\E_4\eAPI.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\internet.fne] [, 1, 0, 0, 1]
这些也在进程里?是不是有问题呀~~
还有就是把这个硬盘挂到别的电脑上,显示一下隐藏文件,查杀一下病毒看看.
wuchuanwei - 2007-6-5 11:32:00
我怎么可能扫错电脑?这就是我的电脑,现在十分头疼!
wuchuanwei - 2007-6-5 11:32:00
我怎么可能扫错电脑?这就是我的电脑,现在十分头疼!
23535254 - 2007-6-5 11:40:00
不要用卡巴!
々一根烟々 - 2007-6-5 14:13:00
搞不懂!!!!!
wuchuanwei - 2007-6-5 15:16:00
我没有用卡巴!我用的是rising
★蓝色尘埃★ - 2007-6-5 21:15:00
头大。
suzhou758 - 2007-6-5 21:45:00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Arp保护神><D:\桌面文件1\arp430.exe> []
<WinnetManager><C:\WINDOWS\system32\WinnetManager.exe> []
启动文件夹
[ip]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\ip.bat --> [N/A]><N>
驱动程序
[arp8023 / arp8023][Stopped/Manual Start]
<\SystemRoot\system32\drivers\arp8023.sys><N/A>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
正在运行的进程
[PID: 508][D:\桌面文件1\arp430.exe] [N/A, ]
[E:\temp\E_4\krnln.fnr] [, 1, 0, 0, 1]
[E:\temp\E_4\iext5.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\sock.fne] [N/A, ]
[E:\temp\E_4\eAPI.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\internet.fne] [, 1, 0, 0, 1]
想办法找到这些删吧,楼主是否可以把那个arp430.exe压缩加密码123后发给我,ryx1191@sina.com 谢谢
wuchuanwei - 2007-6-6 9:45:00
你要的已经发到邮箱,请查收,但我估计这不是病毒,前段时间我们单位局域网有arp病毒,我下载的这个防止攻击。
【ps】我的电脑现在恢复一下系统就好了,硬盘的文件也能看见了,所以我估计还是病毒惹的,能够提供的线索也就前面扫描的日志了,其实病毒对我的影响并不大,我只是特别想知道这是什么原因造成的,还是希望高手能够判断出来
天月来了 - 2007-6-6 10:05:00
[E:\temp\E_4\krnln.fnr] [, 1, 0, 0, 1]
[E:\temp\E_4\iext5.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\sock.fne] [N/A, ]
[E:\temp\E_4\eAPI.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\internet.fne] [, 1, 0, 0, 1]
这个是唯一的东西,其他实在看不出。
不过应该这也不是问题,我估计大多是曾中了毒,被杀软拦住了,但是系统已被搞的不够稳定,所以这结果慢。
新系统里不知还用没用这些东西。
呵呵!!!!!!
suzhou758 - 2007-6-6 10:13:00
噢,恢复了就好了,我等级也是新手上路,处于学习阶段,有误导的地方还请见谅。
© 2000 - 2026 Rising Corp. Ltd.