1   1  /  1  页   跳转

【求助】遇到0.exe之类病毒

【求助】遇到0.exe之类病毒

先前是中了个 SVOHOST.exe

好不容易杀掉,然后又中标了



卡巴不断提示我出现病毒。
名称都是 1.exe  a.exe 0.exe之类的
在temp目录



hijackthis.log:

Logfile of HijackThis v1.99.0
Scan saved at 22:26:19, on 2006-9-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
e:\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
e:\rising\rfw\RfwMain.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
E:\Rising\Rav\RavTask.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
E:\Rising\Rav\RavStub.exe
E:\Kaspersky Anti-Virus 6.0\avp.exe
E:\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\SoftUpdate.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SoftUpdate.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\DOCUME~1\yi\LOCALS~1\Temp\4.exe
C:\Documents and Settings\yi\桌面\HijackThis.exe
C:\DOCUME~1\yi\LOCALS~1\Temp\5.exe

O2 - BHO: (no name) - {D3931E9E-AE61-46B1-99BA-91C438A2C855} - C:\WINDOWS\system32\wp237217.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [RfwMain] "E:\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "E:\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - E:\下载工具\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\下载工具\Thunder\getAllurl.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Tencent\QQ\SendMMS.htm
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBE331D9-E1F9-438E-A660-2944B381E7AD}: NameServer = 202.106.46.151,202.106.0.20
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: 卡巴斯基反病毒6.0 - Kaspersky Lab - E:\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: ForceWare IP service - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: Rising Proxy  Service - Beijing Rising Technology Co., Ltd. - e:\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service - Beijing Rising Technology Co., Ltd. - e:\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\Ravmond.exe
O23 - Service: Update Service For Windows - Unknown - C:\WINDOWS\SoftUpdate.exe




下面是卡巴的扫描
状态    对象    大小
----    ----    ----
感染: 木马程序 Trojan-Downloader.JS.IstBar.ai    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\WPWOUE8K\p1[1].htm    5.7 KB
感染: 木马程序 Trojan-Downloader.JS.IstBar.ai    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\STYZ0L6V\18gou[1].htm    5.7 KB
感染: 木马程序 Trojan-PSW.Win32.Lmir.bai    d:\system volume information\_restore{87ccd2dd-ec3a-4ad9-9767-b4f2a9150c71}\rp7\a0003329.pif    51.6 KB
感染: 木马程序 Trojan.Win32.Qhost.ia    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\STYZ0L6V\theopen[1].exe    19.5 KB
感染: 木马程序 Trojan-Downloader.JS.IstBar.ai    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\LJCDTJGT\uoolink1[1].htm    5.7 KB
感染: 木马程序 Trojan-Downloader.Win32.Small.dtt    C:\DOCUME~1\yi\LOCALS~1\Temp\HttpGetyuletx.exe    24 KB
感染: 木马程序 Trojan-PSW.Win32.Lmir.bai    d:\system volume information\_restore{bb2ce52b-b2fb-40ea-b7d8-ec50fe471970}\rp2\a0000102.pif    51.6 KB
感染: 木马程序 Backdoor.Win32.Hupigon.cgv    C:\DOCUME~1\yi\LOCALS~1\Temp\Setup5018.exe    54 KB
感染: 木马程序 Trojan-PSW.Win32.Delf.qo    C:\DOCUME~1\yi\LOCALS~1\Temp\0.exe    42.5 KB
感染: 木马程序 Trojan.Win32.Qhost.ia    C:\DOCUME~1\yi\LOCALS~1\Temp\1.exe    19.5 KB
感染: 木马程序 Trojan-PSW.Win32.Lmir.bai    d:\system volume information\_restore{87ccd2dd-ec3a-4ad9-9767-b4f2a9150c71}\rp7\a0004337.pif    51.6 KB
感染: 木马程序 Trojan-Downloader.JS.IstBar.ai    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\WPWOUE8K\rich01[1].htm    5.7 KB
感染: 木马程序 Trojan-Downloader.JS.IstBar.ai    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\WPWOUE8K\kuliu[1].htm    5.9 KB
感染: 木马程序 Trojan-PSW.Win32.Lmir.bai    d:\recycler\s-1-5-21-1960408961-1284227242-839522115-1003\dd1.pif    51.6 KB
感染: 广告程序 not-a-virus:AdWare.Win32.Yokbar.b    e:\system volume information\_restore{0dc47bf4-c5f7-4ba8-904a-6c2320131ba5}\rp24\a0001832.dll    224 KB
感染: 木马程序 Trojan-Downloader.Win32.Adload.fu    C:\DOCUME~1\yi\LOCALS~1\Temp\drsmartload964a.exe    24 KB
感染: 广告程序 not-a-virus:AdWare.Win32.Yokbar.a    e:\system volume information\_restore{0dc47bf4-c5f7-4ba8-904a-6c2320131ba5}\rp24\a0001834.exe    28 KB
感染: 木马程序 Trojan-Downloader.Win32.Small.dnb    C:\DOCUME~1\yi\LOCALS~1\Temp\HttpGet.exe    20 KB
感染: 木马程序 Trojan-Downloader.VBS.Psyme.cl    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\WPWOUE8K\ads[1].htm    7.8 KB
感染: 广告程序 not-a-virus:AdWare.Win32.Eztracks.b    C:\Program Files\SearchCar\SearchCar.dll    532 KB
感染: 木马程序 Trojan-PSW.Win32.Lmir.bai    d:\system volume information\_restore{bb2ce52b-b2fb-40ea-b7d8-ec50fe471970}\rp2\a0000105.pif    51.6 KB
感染: 木马程序 Trojan-PSW.Win32.Agent.iu    C:\WINDOWS\system32\nmhxy.dll    56 KB
感染: 木马程序 Trojan-PSW.Win32.Lineage.pj    C:\DOCUME~1\yi\LOCALS~1\Temp\3.exe    35.5 KB
感染: 广告程序 not-a-virus:AdWare.Win32.Yokbar.b    e:\system volume information\_restore{0dc47bf4-c5f7-4ba8-904a-6c2320131ba5}\rp24\a0001833.dll    60 KB
感染: 木马程序 Trojan-Downloader.VBS.Psyme.cl    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\LJCDTJGT\ads[1].htm    7.8 KB
感染: 木马程序 Backdoor.Win32.Hupigon.cgv    C:\Documents and Settings\yi\Local Settings\Temporary Internet Files\Content.IE5\LJCDTJGT\Setup5018[1].exe    54 KB
......




不断出现提示,实在杀不干净,发完这个帖子后又要重新装系统了 >_<
最后编辑2006-09-29 09:38:34
分享到:
gototop
 

C:\WINDOWS\SoftUpdate.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
参考
http://forum.ikaka.com/topic.asp?board=28&artid=8166191
gototop
 

问一下卡吧发现并且删除的
0.exe 1.exe a.exe 也是 SoftUpdate.exe的一部分吗?

就是这些
C:\DOCUME~1\yi\LOCALS~1\Temp\1.exe
C:\DOCUME~1\yi\LOCALS~1\Temp\2.exe
C:\DOCUME~1\yi\LOCALS~1\Temp\5.exe
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT