瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】这几个病毒杀不掉!(附有扫描日志)

123   2  /  3  页   跳转

【求助】这几个病毒杀不掉!(附有扫描日志)

Task Scheduler

+ ACC8DC3B905B4D77.jobc:\documents and settings\smltxh\application data\openbuild\ownsarmybind.exe

HKLM\System\CurrentControlSet\Services

+ DVD-RAM_ServiceService of RAMAsst for Windows XPMatsushita Electric Industrial Co., Ltd.c:\windows\system32\dvdramsv.exe

+ New0c:\windows\system32\new.sys

删除启动项,还用那些not find file项

重启试试
gototop
 

按10朋友做了,还是杀出4个病毒和第一个帖子病毒名和路径一样,不过比以往少了几个,多的时候杀出10个左右,都是第一个帖子所列病毒,高手再多想想办法,先谢谢10楼及各位高手的帮助!
gototop
 

再用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
gototop
 

回12楼高手:请看
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ 00THotkeyFile not found: rem

+ ApointAlps Pointing-device DriverAlps Electric Co., Ltd.c:\program files\apoint2k\apoint.exe

+ ExFiltercdnspiec:\program files\cnnic\cdn\cdnspie.dll

+ ezShieldProtector for PxFile not found: rem

+ HotKeysCmdshkcmd ModuleIntel Corporationc:\windows\system32\hkcmd.exe

+ IgfxTrayigfxTray ModuleIntel Corporationc:\windows\system32\igfxtray.exe

+ PmProxyPmProxyadic:\program files\analog devices\soundmax\pmproxy.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmon.exe

+ RavTrayRavNet TrayRisingd:\program files\rising\rav\ravtray.exe

+ TFNF5File not found: rem

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ DentSecondFile not found: rem

+ DrvMon.exeFile not found: rem

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtFile not found: C:\WINDOWS\System32\hticons.dll

+ PicaViewPicaView 系统扩展 DLLACD Systems, Ltd.d:\program files\acdsee\picaview.dll

+ PowerWord ExplorerBarPowerWord Web Dictionary Engine金山软件股份有限公司d:\program files\kingsoft\powerword 2003\xdictexb.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealOne Player Shell ExtensionsRealNetworksc:\program files\real\realone player\rpshellext.dll

+ TouchED触摸板 开/关 实用程序东芝公司c:\program files\toshiba\touched\touched.dll

+ WinRAR shell extensiond:\program files\winrar\rarext.dll

+ Yahoo!PhotoFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll

+ 粉碎文件File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ywiper.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ PDF Shell ExtensionPDF Shell ExtensionAdobe Systems, Inc.c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ AcroIEHlprObj ClassAdobe Acrobat IE Helper Version 7.0 for ActiveXAdobe Systems Incorporatedc:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll

+ DragSearch BHOFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL

+ Router LayerFile not found: C:\WINDOWS\System32\aclayer.dll

+ ThunderIEHelper Classxunleibho Modulec:\windows\system32\xunleibho_v4.dll

+ {8D629B75-1B9D-6B13-684B-140CF75D4F6A}c:\documents and settings\smltxh\application data\surf five\mediadownload.exe

Task Scheduler

+ ACC8DC3B905B4D77.jobc:\documents and settings\smltxh\application data\openbuild\ownsarmybind.exe

HKLM\System\CurrentControlSet\Services

+ DVD-RAM_ServiceService of RAMAsst for Windows XPMatsushita Electric Industrial Co., Ltd.c:\windows\system32\dvdramsv.exe

+ RavService瑞星杀毒软件网络版客户端通讯代理Beijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravservice.exe

+ RsCCenter瑞星系统通讯中心Beijing Rising Technology Co., Ltd.d:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmond.exe

+ SoundMAX Agent Service (default)SoundMAX service agent componentAnalog Devices, Inc.c:\program files\analog devices\soundmax\smagent.exe

HKLM\System\CurrentControlSet\Services

+ aeaudioAndrea Audio Noise Cancellation DriverAndrea Electronics Corporationc:\windows\system32\drivers\aeaudio.sys

+ ApfiltrServiceAlps Touch Pad DriverAlps Electric Co., Ltd.c:\windows\system32\drivers\apfiltr.sys

+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys

+ E100BNDIS 5.1 driverIntel Corporationc:\windows\system32\drivers\e100b325.sys

+ ExpScanerExpScan.sysd:\program files\rising\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdd:\program files\rising\rav\hookcont.sys

+ HookRegd:\program files\rising\rav\hookreg.sys

+ hooksys瑞星d:\program files\rising\rav\hooksys.sys

+ ialmController Hub for Intel Graphics DriverIntel Corporationc:\windows\system32\drivers\ialmnt5.sys

+ New0c:\windows\system32\new.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ PxHelp20Px Engine Device Driver for Windows 2000/XPSonic Solutionsc:\windows\system32\drivers\pxhelp20.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ smwdmSoundMAX Integrated Digital Audio Analog Devices, Inc.c:\windows\system32\drivers\smwdm.sys

+ SONYPVU1Sony USB Lower Filter driverSony Corporationc:\windows\system32\drivers\sonypvu1.sys

+ TOSHIBASoftModemSoftModem Device DriverLTc:\windows\system32\drivers\ltsm.sys

+ TVALDToshiba ACPI-Based Value Added Logical Device DriverToshiba Corporationc:\windows\system32\drivers\tvald.sys

+ TVALGTOSHIBA Value Added Logical and General Purpose Device DriverTOSHIBA Corporationc:\windows\system32\drivers\tvalg.sys

+ {6080A529-897E-4629-A488-ABA0C29B635E}Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\windows\system32\drivers\ialmsbw.sys

+ {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\windows\system32\drivers\ialmkchw.sys

+ {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}Ch7009 MinidriverIntel Corporationc:\windows\system32\drivers\wa301a.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls

+ APIHookDll.dllFile not found: APIHookDll.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ igfxcuiigfxsrvc ModuleIntel Corporationc:\windows\system32\igfxsrvc.dll

HKCU\Control Panel\Desktop\Scrnsave.exe

+ C:\WINDOWS\System32\NIAGAR~1.SCRUltra Screen Saver Maker Core ApplicationFinalhit Ltdc:\windows\system32\niagarafalls.scr

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ EPSON V3 2KMonitor363EPSON Bidirectional MonitorSEIKO EPSON CORPORATIONc:\windows\system32\e_sl2363.dll

gototop
 

+ ACC8DC3B905B4D77.jobc:\documents and settings\smltxh\application data\openbuild\ownsarmybind.exe
+ DVD-RAM_ServiceService of RAMAsst for Windows XPMatsushita Electric Industrial Co., Ltd.c:\windows\system32\dvdramsv.exe

这两个怎么还在,是楼主安装的嘛

+ New0c:\windows\system32\new.sys

还有那些File not found好像没删除干净
gototop
 

回14楼朋友:我按你上面做了,重起后杀毒发现还有11个,就是第一个帖子的3种,下面是我重新弄的日志,请看:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ ApointAlps Pointing-device DriverAlps Electric Co., Ltd.c:\program files\apoint2k\apoint.exe

+ ExFiltercdnspiec:\program files\cnnic\cdn\cdnspie.dll

+ HotKeysCmdshkcmd ModuleIntel Corporationc:\windows\system32\hkcmd.exe

+ IgfxTrayigfxTray ModuleIntel Corporationc:\windows\system32\igfxtray.exe

+ PmProxyPmProxyadic:\program files\analog devices\soundmax\pmproxy.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmon.exe

+ RavTrayRavNet TrayRisingd:\program files\rising\rav\ravtray.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtFile not found: C:\WINDOWS\System32\hticons.dll

+ PicaViewPicaView 系统扩展 DLLACD Systems, Ltd.d:\program files\acdsee\picaview.dll

+ PowerWord ExplorerBarPowerWord Web Dictionary Engine金山软件股份有限公司d:\program files\kingsoft\powerword 2003\xdictexb.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealOne Player Shell ExtensionsRealNetworksc:\program files\real\realone player\rpshellext.dll

+ TouchED触摸板 开/关 实用程序东芝公司c:\program files\toshiba\touched\touched.dll

+ WinRAR shell extensiond:\program files\winrar\rarext.dll

+ Yahoo!PhotoFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll

+ 粉碎文件File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ywiper.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ PDF Shell ExtensionPDF Shell ExtensionAdobe Systems, Inc.c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ AcroIEHlprObj ClassAdobe Acrobat IE Helper Version 7.0 for ActiveXAdobe Systems Incorporatedc:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll

+ ThunderIEHelper Classxunleibho Modulec:\windows\system32\xunleibho_v4.dll

+ {8D629B75-1B9D-6B13-684B-140CF75D4F6A}c:\documents and settings\smltxh\application data\surf five\mediadownload.exe

HKLM\System\CurrentControlSet\Services

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmond.exe

+ SoundMAX Agent Service (default)SoundMAX service agent componentAnalog Devices, Inc.c:\program files\analog devices\soundmax\smagent.exe

HKLM\System\CurrentControlSet\Services

+ aeaudioAndrea Audio Noise Cancellation DriverAndrea Electronics Corporationc:\windows\system32\drivers\aeaudio.sys

+ ApfiltrServiceAlps Touch Pad DriverAlps Electric Co., Ltd.c:\windows\system32\drivers\apfiltr.sys

+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys

+ E100BNDIS 5.1 driverIntel Corporationc:\windows\system32\drivers\e100b325.sys

+ ExpScanerExpScan.sysd:\program files\rising\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdd:\program files\rising\rav\hookcont.sys

+ HookRegd:\program files\rising\rav\hookreg.sys

+ hooksys瑞星d:\program files\rising\rav\hooksys.sys

+ ialmController Hub for Intel Graphics DriverIntel Corporationc:\windows\system32\drivers\ialmnt5.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ PxHelp20Px Engine Device Driver for Windows 2000/XPSonic Solutionsc:\windows\system32\drivers\pxhelp20.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ smwdmSoundMAX Integrated Digital Audio Analog Devices, Inc.c:\windows\system32\drivers\smwdm.sys

+ SONYPVU1Sony USB Lower Filter driverSony Corporationc:\windows\system32\drivers\sonypvu1.sys

+ TOSHIBASoftModemSoftModem Device DriverLTc:\windows\system32\drivers\ltsm.sys

+ TVALDToshiba ACPI-Based Value Added Logical Device DriverToshiba Corporationc:\windows\system32\drivers\tvald.sys

+ TVALGTOSHIBA Value Added Logical and General Purpose Device DriverTOSHIBA Corporationc:\windows\system32\drivers\tvalg.sys

+ {6080A529-897E-4629-A488-ABA0C29B635E}Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\windows\system32\drivers\ialmsbw.sys

+ {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\windows\system32\drivers\ialmkchw.sys

+ {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}Ch7009 MinidriverIntel Corporationc:\windows\system32\drivers\wa301a.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ igfxcuiigfxsrvc ModuleIntel Corporationc:\windows\system32\igfxsrvc.dll

HKCU\Control Panel\Desktop\Scrnsave.exe

+ C:\WINDOWS\System32\NIAGAR~1.SCRUltra Screen Saver Maker Core ApplicationFinalhit Ltdc:\windows\system32\niagarafalls.scr

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ EPSON V3 2KMonitor363EPSON Bidirectional MonitorSEIKO EPSON CORPORATIONc:\windows\system32\e_sl2363.dll
gototop
 

+ {8D629B75-1B9D-6B13-684B-140CF75D4F6A}c:\documents and settings\smltxh\application data\surf five\mediadownload.exe

删除试试

若还不行看看有http://forum.ikaka.com/topic.asp?board=28&artid=7538008没有帮助
gototop
 

回16楼高手:照上做了,再查毒没发现有,我再观察下,看是否能杜绝这个病毒了,非常感谢!!!
gototop
 

楼上BlackStone不愧为高手,你最后一个办法象杀手裥,今天我查毒没有了!为什么前面几个修改不行,而后面一个就可以了?先谢谢高手了!!!
gototop
 

再请高手看看经过前面修改后的扫描日志,看有问题么?谢谢!
HijackThis_815汉化版扫描日志 V1.99.1
保存于      11:58:21, 日期 2005-12-15
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\WINDOWS\Explorer.EXE
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\Rundll32.exe
D:\Program Files\Rising\Rav\RavMon.exe
D:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\conime.exe
D:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
D:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe

O2 - BHO: yPhtb - _{33BBE430-0E42-4f12-B075-8D21ACB10DCB} - (no file)
O2 - BHO: (no name) - _{AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4}? - (no file)
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - 启动项HKLM\\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - 启动项HKLM\\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - 启动项HKLM\\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll",ExecFilter solo
O4 - 启动项HKLM\\Run: [RavMon] d:\Program Files\Rising\Rav\RavMon.exe -system
O4 - 启动项HKLM\\Run: [RavTray] d:\Program Files\Rising\Rav\RavTray.exe
O4 - 启动项HKLM\\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - 浏览器额外的按钮: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - d:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {3A2B370C-BA0A-11D1-B137-0000F8753F5D} (Microsoft Chart Control 6.0 (SP4) (OLEDB)) - http://www.ehomeday.com/jy/mschart.cab
O16 - DPF: {48FE89A0-486C-48DF-9DEC-BED22BDC6057} (XIsOro Control) - http://www.sinago.com/download/OroCheck.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1134528314330
O18 - 列举现有的协议: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - d:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT