瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 传奇世界游戏帐号被盗后马上扫描的日志,高手进来看下

1   1  /  1  页   跳转

传奇世界游戏帐号被盗后马上扫描的日志,高手进来看下

传奇世界游戏帐号被盗后马上扫描的日志,高手进来看下

这个是我的游戏帐号被盗后三分钟扫描的日志,电脑配制CUP奔四2.4B,512内存,运行奇慢,里面肯定有木马或病毒,可是瑞星一直找不到,在安全模式下也是一样,

Logfile of HijackThis v1.99.1
Scan saved at 23:50:07, on 2005-12-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\RISING\RAV\Ravmond.exe
E:\RISING\RAV\RavStub.exe
e:\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
e:\Rising\Rfw\RfwMain.exe
E:\Rising\Rav\RavMon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\RISING\RAV\RAVTIMER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
E:\RISING\RAV\CCENTER.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
E:\Tencent\QQ.exe
E:\Tencent\TIMPlatform.exe
E:\Shanda\Woool\woool.exe
E:\Shanda\Woool\data\woool.dat
E:\Shanda\Woool\data\wooolwg.dat
F:\新建文件夹\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v8.dll
O4 - HKLM\..\Run: [瑞星监控] E:\Rising\Rav\RavMon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTimer] E:\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] E:\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - E:\迅雷\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\迅雷\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\Tencent\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Tencent\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Tencent\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Tencent\SendMMS.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - E:\浩方\浩方对战平台\GameClient.exe
O9 - Extra 'Tools' menuitem: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - E:\浩方\浩方对战平台\GameClient.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Tencent\QQ.EXE
O9 - Extra 'Tools' menuitem: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Tencent\QQ.EXE
O9 - Extra button: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Tencent\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Tencent\QQIEHelper.dll
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {0400AC1C-EEF0-4638-A501-31D5A0DC2002} (VTPlug3 Class) - http://202.101.62.195:1995/VTrans.cab
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://61.129.90.93:1995/talk.cab
O16 - DPF: {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} (LoaderCore Class) - http://tb.sogou.com/DLLoader.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{965EEDEB-3BCE-4396-9FD7-EBE55FBF69E3}: NameServer = 202.96.128.86
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - e:\Rising\Rfw\rfwsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - E:\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\RISING\RAV\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
最后编辑2005-12-06 20:33:33
分享到:
gototop
 

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
这个应该是Win32.Troj.RootKit (内核木马)的 服务进程  把它停掉 在开始菜单里面 运行 - msconfig  有个服务项 找到 并停用它 然后删掉
C:\Program Files\WinPcap\rpcapd.ini
gototop
 

呵呵~~~~~~,原来是你啊,我的QQ你加了吗??你的QQ昵称是不是叫缠绵,我找不到那个文件,C:\Program Files没有WinPcap这个文件夹,我用搜索也找不到rpcapd.ini这个文件,
我今天下了个卡巴,刚才弑毒弑出来是这样的:E:\Shanda\Woool\Data\wsock32.dll是特洛伊木马Trojan-PSW.Win32.Lmir.aoe.然后就是说对象无法清除,清除被延迟.还有一个就是E:\System Volume Information\_restore{81C89687-E86A-4EE2-9A36-5164F4FB9777}\RP45\A0029047.dll是特洛伊木马,然后也是无法清除,清除被延迟,
这个木马弄得我好痛苦啊,现在终于找到它了,我还说如果再搞不好的话就把硬盘格式化了重装系统,不过现在有点对瑞星失望了,它什么都查不到,
gototop
 

你先禁了那个服务!  然后进注册表(开始-运行-regedit) 然后编辑-查找- a002947.dll wsock32.dll
删掉有关键值     
搞好了  重启 进安全模式  删掉E:\Shanda\Woool\Data\wsock32.dll  E:\System Volume Information\_restore{81C89687-E86A-4EE2-9A36-5164F4FB9777}\RP45\A0029047.dll
gototop
 

哦,我还是有点不明白,就是我怎么看它那个是有关的键值啊,我怕删错了
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT