瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 无能的瑞星,我跟你永远说再见,滚吧

1   1  /  1  页   跳转

无能的瑞星,我跟你永远说再见,滚吧

无能的瑞星,我跟你永远说再见,滚吧

该用户帖子内容已被屏蔽
最后编辑2006-07-03 14:03:27.153000000
分享到:
gototop
 

安全模式下使用专杀......
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=8105899
下载HijackThis...把日志帖上来..

专杀无效...
gototop
 

该用户帖子内容已被屏蔽
gototop
 

引用:
【7633333的贴子】Logfile of HijackThis v1.99.1
Scan saved at  1:10:26, on 2006-07-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\软件\瑞星\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\软件\瑞星\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
d:\软件\瑞星防火墙\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\软件\瑞星\Rising\Rav\RavStub.exe
d:\软件\瑞星防火墙\rising\rfw\RfwMain.exe
D:\软件\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\VTTimer.exe
D:\软件\瑞星\Rising\Rav\RavTask.exe
D:\软件\瑞星\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\软件\Maxthon\Maxthon.exe
D:\软件\迅雷\Program\Thunder5.exe
D:\本电脑文档包\下载后专用\ha_hijackthis_1991\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 61.237.229.5 bbs.btbbt.com
O1 - Hosts: 222.73.250.181 www.t2ns.com
O1 - Hosts: 218.93.127.202 bbs.crsky.com
O1 - Hosts: 219.136.244.111 www.pcgames.com.cn
O1 - Hosts: 211.99.190.24 www.luanshi.com.cn
O1 - Hosts: 61.153.8.12 bbs.mumayi.net
O1 - Hosts: 219.153.14.19 www.f130.net
O1 - Hosts: 219.153.14.19 www.f130.net
O1 - Hosts: 64.20.33.115 www.52yn.net
O1 - Hosts: 211.99.190.37 flash.leyuan.com
O1 - Hosts: 61.172.206.76 www.7k7k.com
O1 - Hosts: 218.6.196.9 www.flash114.net
O1 - Hosts: 58.211.236.173 www.100flash.com
O1 - Hosts: 60.191.254.147 www.xuanxuan.com
O1 - Hosts: 219.153.36.170 www.flash8.com
O1 - Hosts: 210.73.88.170 www.flashempire.com
O1 - Hosts: 61.153.48.247 www.mtvsite.com
O1 - Hosts: 61.136.194.212 www.y98.cn
O1 - Hosts: 218.16.124.124 www.mtvyy.com
O1 - Hosts: 58.215.64.142 www.forclear.com
O1 - Hosts: 61.129.35.147 www.tttmtv.com
O1 - Hosts: 61.152.116.72 bt3.btchina.net
O1 - Hosts: 61.172.245.231 www.xbt.com.cn
O1 - Hosts: 222.36.47.42 www.ttbt.cn
O1 - Hosts: 219.153.42.87 www.xunlei.com
O1 - Hosts: 218.5.76.219 bt.fkee.com
O1 - Hosts: 218.83.159.244 www.5u6.net
O1 - Hosts: 222.170.103.147 cluster2.gbaopan.com
O1 - Hosts: 61.155.107.205 www.k65.net
O1 - Hosts: 61.129.78.16 www.oktoon.com
O1 - Hosts: 211.91.135.214 www.pc2n.com
O1 - Hosts: 60.12.128.73 www.aniface.com
O1 - Hosts: 60.191.14.12 www.yupoo.com
O1 - Hosts: 61.153.8.12 bbs.mumayi.net
O1 - Hosts: 61.152.167.125 www.ishare.com.cn
O1 - Hosts: 61.140.60.83 et.21cn.com
O1 - Hosts: 219.239.89.28 www.enet.com.cn
O1 - Hosts: 202.75.223.52 xok.cn
O1 - Hosts: 60.190.68.12 www.letget.com
O1 - Hosts: 202.102.229.174 cndesk.com
O1 - Hosts: 222.36.44.137 desk.itbulo.com
O1 - Hosts: 219.239.88.126 desktop.yesky.com
O1 - Hosts: 220.164.140.173 desk.hdskin.com
O1 - Hosts: 210.74.232.218 www.newxzn.com
O1 - Hosts: 219.148.120.141 www.wallcoo.com
O1 - Hosts: 218.30.75.42 desk.poptang.com
O1 - Hosts: 202.102.200.123 www.51wall.com
O1 - Hosts: 61.233.41.218 www.mydeskcity.com
O1 - Hosts: 60.190.222.233 skin.520vc.com
O1 - Hosts: 218.5.79.156 www.123cha.com
O1 - Hosts: 61.140.99.11 gd.ct10000.com
O1 - Hosts: 221.238.198.83 www.120ask.com
O1 - Hosts: 219.137.2.4 benchmark.avl.com.cn
O1 - Hosts: 221.238.198.20 www3.allfang.com
O1 - Hosts: 61.152.160.184 www.oasishair98.cn
O1 - Hosts: 219.136.247.86 www.gzbufa.com
O1 - Hosts: 218.30.109.149 rent.gz.soufun.com
O1 - Hosts: 61.144.67.74 www.cityxy.com
O1 - Hosts: 211.157.0.210 www.moxoo.com
O1 - Hosts: 221.231.138.33 www.blkbf.com
O1 - Hosts: 222.189.228.34 www.51higher.com
O1 - Hosts: 218.16.117.81 www.szlixiang888.com
O1 - Hosts: 61.186.250.129 www.163888.net
O1 - Hosts: 218.16.123.81 ok.21cn.com
O1 - Hosts: 60.191.249.14 www.9158.com
O1 - Hosts: 222.242.71.91 www.91kg.com
O1 - Hosts: 61.233.119.54 tt.banzou.cn
O1 - Hosts: 61.152.249.95 www.wo99.com
O1 - Hosts: 61.143.211.202 www.yyfc.com
O1 - Hosts: 61.236.229.18 www.happy369.net
O1 - Hosts: 218.246.177.205 www.xianlai.com
O1 - Hosts: 61.186.250.129 www.163888.net
O1 - Hosts: 222.242.71.91 yy22.91kg.com
O1 - Hosts: 218.78.211.159 www.xq530.com
O1 - Hosts: 211.100.32.49 music.mop.com
O1 - Hosts: 61.152.255.69 www.51mike.com
O1 - Hosts: 61.145.121.85 www2.3g.net.cn
O1 - Hosts: 61.131.96.31 club.mypda.com.cn
O1 - Hosts: 61.131.96.31 club.mypda.com.cn
O1 - Hosts: 219.146.1.212 bbs.tvren.com
O1 - Hosts: 222.38.97.66 bbs.pdafans.com
O1 - Hosts: 222.38.97.66 bbs.pdafans.com
O1 - Hosts: 61.151.249.244 www.51haha.net
O1 - Hosts: 222.36.41.158 www.wda.com.cn
O1 - Hosts: 219.129.20.86 www.aryaya.com
O1 - Hosts: 222.36.47.3 www.tompda.com
O1 - Hosts: 61.157.96.151 www.life1126.com
O1 - Hosts: 222.38.97.66 bbs.pdafans.com
O1 - Hosts: 222.36.41.132 bbs.mpfans.com
O1 - Hosts: 222.36.41.158 www.wda.com.cn
O1 - Hosts: 203.86.167.53 www.pxdxa.com
O1 - Hosts: 61.152.169.71 www.hi-pda.com
O1 - Hosts: 218.200.244.98 www.monternet.com
O1 - Hosts: 220.181.31.3 kj1.nease.net
O1 - Hosts: 211.156.193.130 www.ems.com.cn
O1 - Hosts: 61.135.154.25 photo.monternet.com
O1 - Hosts: 218.5.79.156 www.123cha.com
O1 - Hosts: 222.36.45.118 www.imobile.com.cn
O1 - Hosts: 219.72.227.12 www.soeasy.net.cn
O1 - Hosts: 219.133.36.188 www.24sun.com
O1 - Hosts: 218.17.247.222 www.cctv.com
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\软件\迅雷\ComDlls\XunLeiBHO_002.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - (no file)
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - (no file)
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [RavTask] "D:\软件\瑞星\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\软件\瑞星防火墙\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\RunOnce: [RavStub] "D:\软件\瑞星\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - D:\软件\迅雷\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\软件\迅雷\Program\GetAllUrl.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\espi11.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\espi11.dll
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} (PowerPlayer Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {88734439-46D0-42C0-A13F-7E881EE550CF} - http://www.bluesky.cn/download/filetran.cab
O16 - DPF: {AB89C9BF-9250-473B-BE49-D34F615CB678} (Chaos Filter) - http://download.mysee.com/Chaos.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{66CCD8C3-65C9-4B33-9A66-C2F559D4632A}: NameServer = 202.96.128.86 202.96.128.166
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BDBD085-EB55-4DA4-AE9D-EC55ADFCF820}: NameServer = 222.73.1.224
O23 - Service: ewido security suite control - ewido networks - D:\软件\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\软件\瑞星防火墙\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\软件\瑞星防火墙\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\软件\瑞星\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\软件\瑞星\Rising\Rav\Ravmond.exe
O23 - Service:   - Unknown owner - C:\WINDOWS\servter.exe


...........................


01项好乱呀......
O23 - Service:   - Unknown owner - C:\WINDOWS\servter.exe灰鸽子的服务项
gototop
 

O1 - Hosts: 61.237.229.5 bbs.btbbt.com
O1 - Hosts: 222.73.250.181 www.t2ns.com
O1 - Hosts: 218.93.127.202 bbs.crsky.com
O1 - Hosts: 219.136.244.111 www.pcgames.com.cn
O1 - Hosts: 211.99.190.24 www.luanshi.com.cn
O1 - Hosts: 61.153.8.12 bbs.mumayi.net
O1 - Hosts: 219.153.14.19 www.f130.net
O1 - Hosts: 219.153.14.19 www.f130.net
O1 - Hosts: 64.20.33.115 www.52yn.net
O1 - Hosts: 211.99.190.37 flash.leyuan.com
O1 - Hosts: 61.172.206.76 www.7k7k.com
O1 - Hosts: 218.6.196.9 www.flash114.net
O1 - Hosts: 58.211.236.173 www.100flash.com
O1 - Hosts: 60.191.254.147 www.xuanxuan.com
O1 - Hosts: 219.153.36.170 www.flash8.com
O1 - Hosts: 210.73.88.170 www.flashempire.com
O1 - Hosts: 61.153.48.247 www.mtvsite.com
O1 - Hosts: 61.136.194.212 www.y98.cn
O1 - Hosts: 218.16.124.124 www.mtvyy.com
O1 - Hosts: 58.215.64.142 www.forclear.com
O1 - Hosts: 61.129.35.147 www.tttmtv.com
O1 - Hosts: 61.152.116.72 bt3.btchina.net
O1 - Hosts: 61.172.245.231 www.xbt.com.cn
O1 - Hosts: 222.36.47.42 www.ttbt.cn
O1 - Hosts: 219.153.42.87 www.xunlei.com
O1 - Hosts: 218.5.76.219 bt.fkee.com
O1 - Hosts: 218.83.159.244 www.5u6.net
O1 - Hosts: 222.170.103.147 cluster2.gbaopan.com
O1 - Hosts: 61.155.107.205 www.k65.net
O1 - Hosts: 61.129.78.16 www.oktoon.com
O1 - Hosts: 211.91.135.214 www.pc2n.com
O1 - Hosts: 60.12.128.73 www.aniface.com
O1 - Hosts: 60.191.14.12 www.yupoo.com
O1 - Hosts: 61.153.8.12 bbs.mumayi.net
O1 - Hosts: 61.152.167.125 www.ishare.com.cn
O1 - Hosts: 61.140.60.83 et.21cn.com
O1 - Hosts: 219.239.89.28 www.enet.com.cn
O1 - Hosts: 202.75.223.52 xok.cn
O1 - Hosts: 60.190.68.12 www.letget.com
O1 - Hosts: 202.102.229.174 cndesk.com
O1 - Hosts: 222.36.44.137 desk.itbulo.com
O1 - Hosts: 219.239.88.126 desktop.yesky.com
O1 - Hosts: 220.164.140.173 desk.hdskin.com
O1 - Hosts: 210.74.232.218 www.newxzn.com
O1 - Hosts: 219.148.120.141 www.wallcoo.com
O1 - Hosts: 218.30.75.42 desk.poptang.com
O1 - Hosts: 202.102.200.123 www.51wall.com
O1 - Hosts: 61.233.41.218 www.mydeskcity.com
O1 - Hosts: 60.190.222.233 skin.520vc.com
O1 - Hosts: 218.5.79.156 www.123cha.com
O1 - Hosts: 61.140.99.11 gd.ct10000.com
O1 - Hosts: 221.238.198.83 www.120ask.com
O1 - Hosts: 219.137.2.4 benchmark.avl.com.cn
O1 - Hosts: 221.238.198.20 www3.allfang.com
O1 - Hosts: 61.152.160.184 www.oasishair98.cn
O1 - Hosts: 219.136.247.86 www.gzbufa.com
O1 - Hosts: 218.30.109.149 rent.gz.soufun.com
O1 - Hosts: 61.144.67.74 www.cityxy.com
O1 - Hosts: 211.157.0.210 www.moxoo.com
O1 - Hosts: 221.231.138.33 www.blkbf.com
O1 - Hosts: 222.189.228.34 www.51higher.com
O1 - Hosts: 218.16.117.81 www.szlixiang888.com
O1 - Hosts: 61.186.250.129 www.163888.net
O1 - Hosts: 218.16.123.81 ok.21cn.com
O1 - Hosts: 60.191.249.14 www.9158.com
O1 - Hosts: 222.242.71.91 www.91kg.com
O1 - Hosts: 61.233.119.54 tt.banzou.cn
O1 - Hosts: 61.152.249.95 www.wo99.com
O1 - Hosts: 61.143.211.202 www.yyfc.com
O1 - Hosts: 61.236.229.18 www.happy369.net
O1 - Hosts: 218.246.177.205 www.xianlai.com
O1 - Hosts: 61.186.250.129 www.163888.net
O1 - Hosts: 222.242.71.91 yy22.91kg.com
O1 - Hosts: 218.78.211.159 www.xq530.com
O1 - Hosts: 211.100.32.49 music.mop.com
O1 - Hosts: 61.152.255.69 www.51mike.com
O1 - Hosts: 61.145.121.85 www2.3g.net.cn
O1 - Hosts: 61.131.96.31 club.mypda.com.cn
O1 - Hosts: 61.131.96.31 club.mypda.com.cn
O1 - Hosts: 219.146.1.212 bbs.tvren.com
O1 - Hosts: 222.38.97.66 bbs.pdafans.com
O1 - Hosts: 222.38.97.66 bbs.pdafans.com
O1 - Hosts: 61.151.249.244 www.51haha.net
O1 - Hosts: 222.36.41.158 www.wda.com.cn
O1 - Hosts: 219.129.20.86 www.aryaya.com
O1 - Hosts: 222.36.47.3 www.tompda.com
O1 - Hosts: 61.157.96.151 www.life1126.com
O1 - Hosts: 222.38.97.66 bbs.pdafans.com
O1 - Hosts: 222.36.41.132 bbs.mpfans.com
O1 - Hosts: 222.36.41.158 www.wda.com.cn
O1 - Hosts: 203.86.167.53 www.pxdxa.com
O1 - Hosts: 61.152.169.71 www.hi-pda.com
O1 - Hosts: 218.200.244.98 www.monternet.com
O1 - Hosts: 220.181.31.3 kj1.nease.net
O1 - Hosts: 211.156.193.130 www.ems.com.cn
O1 - Hosts: 61.135.154.25 photo.monternet.com
O1 - Hosts: 218.5.79.156 www.123cha.com
O1 - Hosts: 222.36.45.118 www.imobile.com.cn
O1 - Hosts: 219.72.227.12 www.soeasy.net.cn
O1 - Hosts: 219.133.36.188 www.24sun.com
O1 - Hosts: 218.17.247.222 www.cctv.com
修复所有01项

O23 - Service:   - Unknown owner - C:\WINDOWS\servter.exe
1.开始-运行输入regedit,打开注册表编辑器,定位到HKEY_LOCAL_MACHINE\ SYSTEM \ CURRENTCONTROLSET \ SERVICES分支,删除左栏中的病毒服务名"   " (注意是几个空格)
2.重启系统,在“文件夹选项”的“查看”面板中勾选“显示系统文件”、“显示所有的文件和文件夹”两项,点击“确定”按钮。然后在%windows%下寻找病毒文件名C:\WINDOWS\servter.exe,C:\WINDOWS\servter.dll,C:\WINDOWS\servter_Hook.dll,C:\WINDOWS\servterkey.dll,能找到的都删除





自已系统搞得像狗窝一样还说瑞星怎么样.
爱用不用.你要能用其它杀软能把这只鸽子杀了,那就算它狠.
什么玩意.
gototop
 

补充修复:
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - (no file)
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - (no file)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


O10 - Unknown file in Winsock LSP: c:\windows\system32\espi11.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\espi11.dll
这项不能用HijackThis直接修复
参考http://forum.ikaka.com/topic.asp?board=28&artid=7259392
其中关于HijackThis日志中O10项的处理方法
用LSPFix删除c:\windows\system32\espi11.dll,如果重启后导致不能上网,再用WinsockXPFix来修复。

这种一眼能看出来的灰鸽子,说是“高手的天敌”简直是让人笑掉大牙,因为我们都不算高手,只是有点经验的菜鸟都能把它搞掉。瑞星正在测试的增强版引擎应该能杀这玩意。楼主自己把机子搞成这样,怪谁都没用,只能怪自己安全意识不强。拜托楼主以后说话客气一点,不要故作惊人之语,你这样说,别人不会认为你牛,只会反感。
gototop
 

灰鸽子VIP2006版本  带键盘记录器  建议你还是重装下比较好

注意系统补丁    教你手动清除  会把你说糊涂的
gototop
 

引用:
【心舒贝贝的贴子】灰鸽子VIP2006版本  带键盘记录器  建议你还是重装下比较好

注意系统补丁    教你手动清除  会把你说糊涂的
...........................

个人认为这灰鸽子只是老版加个壳而已,VIP2006版的HijackThis是看不到的,要用其他工具才行。还有,手动清除,说到底就那么几分钟的事,加上重启也没多久。一中病毒就重装,那更没有道理。
gototop
 

引用:
【心舒贝贝的贴子】灰鸽子VIP2006版本  带键盘记录器  建议你还是重装下比较好

注意系统补丁    教你手动清除  会把你说糊涂的
...........................

它中的是最原始的鸽子.用不着重装.
当然如果连那么简单的几步也不会做的话那我们也没办法.

如果那么几步都不会的话估计重装系统也会请人吧.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT