1   1  /  1  页   跳转

中了类似熊猫的病毒~~~求救~~~

中了类似熊猫的病毒~~~求救~~~

电脑中了类似熊猫的病毒,不同点是没有改变图标,点击进入C,D...盘的时候瑞星提示发现疑似脚本病毒,其名称为:"C:\WINDOWS\system32\wscript.exe" .MS32DLL.dll.vbs",我选择跳过脚本,只能用右键点"打开"进入.看任务管理器,进程中也有"spoolsv"在执行.
现在我的瑞星智能监控的邮件发送和接收监控都已经被禁用,无法启动,求各位高人施以援助之手,他日定当涌泉相报!
最后编辑2007-02-20 14:53:45
分享到:
gototop
 

补充一点:每次开机的时候会显示" MS32DLL.dll.vbs 有多个扩展名,其中一个是 .vbs ......"什么的
gototop
 

怎么没有人理我啊~顶一下下~急ing~~~~
gototop
 

用SER扫下系统,把日志贴上来
SER的使用方法看这里
http://forum.ikaka.com/topic.asp?board=28&artid=8270267
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [(Verified)Microsoft Corporation]
    <Skype><"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized>  [(Verified)N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <Apoint><C:\Program Files\Apoint\Apoint.exe>  [(Verified)Alps Electric Co., Ltd.]
    <SunJavaUpdateSched><C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe>  [N/A]
    <IntelWireless><C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless>  [N/A]
    <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <Dell QuickSet><C:\Program Files\Dell\QuickSet\quickset.exe>  [Dell Inc]
    <DVDLauncher><"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe">  [CyberLink Corp.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <KillTrojanMaster><C:\木马专杀大师\木马专杀大师.exe>  [N/A]
    <UpdateManager><"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r>  [Sonic Solutions]
    <BigDog305><C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)>  [N/A]
    <New.net Startup><rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s>  [N/A]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)RealNetworks, Inc.]
    <QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
    <iTunesHelper><"C:\Program Files\iTunes\iTunesHelper.exe">  [(Verified)Apple Computer, Inc.]
    <runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <WebThunder><C:\Program Files\Thunder Network\WebThunder\WebThunder.exe>  [深圳市迅雷网络技术有限公司]
    <winboot><wscript.exe /E:vbs C:\WINDOWS\boot.ini>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><>  [N/A]
    <{F584A094-D920-4010-9EE3-940A4396A4F8}><C:\WINDOWS\system32\Hheiqz.dll>  [N/A]
    <{3C62C6CB-6D88-460B-AB6A-F8372BDA515F}><C:\WINDOWS\system32\Gnyhg.dll>  [N/A]
    <{19C2B337-A55F-49AC-9D64-558C91850C03}><C:\WINDOWS\system32\Oefnfa.dll>  [N/A]
    <{395AECB8-C9F2-4E89-85D9-B0282548EA2F}><C:\WINDOWS\system32\Gyngi.dll>  [N/A]
    <{331B49D8-8FDD-486D-909D-71423C9B7935}><C:\WINDOWS\system32\Enpmlj.dll>  [N/A]
    <{E772756B-1C95-4427-B8BE-5A464FBAB241}><C:\WINDOWS\system32\Sivjc.dll>  [N/A]
    <{25C5AD02-DA3C-4464-B704-E107F22990A2}><C:\WINDOWS\system32\Dxfmx.dll>  [N/A]
    <{C871091E-1FF2-408E-A85B-B935B23E4748}><C:\WINDOWS\system32\Yxni.dll>  [N/A]
    <{60748CD7-1076-46DC-84C9-7976F4721E89}><C:\WINDOWS\system32\Kkcwc.dll>  [N/A]
    <{343BE343-BD8F-4BFF-9914-546DB443E111}><C:\WINDOWS\system32\Mvpp.dll>  [N/A]
    <{BF0BF363-CF72-402F-95E4-762A433E1E39}><C:\WINDOWS\system32\Araita.dll>  [N/A]
    <{A6685A0F-143D-4019-A638-DCE165B845AF}><C:\WINDOWS\system32\Oabshi.dll>  [N/A]
    <{054058EF-6E7A-4D0B-8C17-560883BF6846}><C:\WINDOWS\system32\Qpko.dll>  [N/A]
    <{B5626087-DFB4-43A5-873D-59F204946663}><C:\WINDOWS\system32\Xceaje.dll>  [N/A]
    <{77045EE4-BC55-4755-8AC5-ADFB3238DFCF}><C:\WINDOWS\system32\Qipcs.dll>  [N/A]
    <{E0139903-139E-4FCC-9A96-747397B0D896}><C:\WINDOWS\system32\Qmzwf.dll>  [N/A]
    <{DAD633F7-E1B4-433D-8733-D9CA4200E8B4}><C:\WINDOWS\system32\Xnpev.dll>  [N/A]
    <{49DB541D-A9B1-49EA-AEFC-D3D77707AEED}><C:\WINDOWS\system32\Ktqcef.dll>  [N/A]
    <{2E802E9F-DEA5-4477-8153-27F15BD2C933}><C:\WINDOWS\system32\Nmso.dll>  [N/A]
    <{B9E4D1CA-6CAF-4E2A-9F79-60A1F2EE1951}><C:\WINDOWS\system32\Ltcv.dll>  [N/A]
    <{83C77F8D-B379-4793-837F-C71EFAE8ADD0}><C:\WINDOWS\system32\Xlabuh.dll>  [N/A]
    <{72B7250F-4FB3-4791-863F-E594198F0921}><C:\WINDOWS\system32\Mkavo.dll>  [N/A]
    <{A6CD8965-EF1B-4C6D-9064-2546986DD5F5}><C:\WINDOWS\system32\Iyup.dll>  [N/A]
    <{0A9BDF42-4C06-4183-BAC9-D86F0967C9BF}><C:\WINDOWS\system32\Qdspuo.dll>  [N/A]
    <{0693FAEC-616C-48DF-8755-17ACB64C89F6}><C:\WINDOWS\system32\Mxklr.dll>  [N/A]
    <{83F0734B-649F-4C70-9D24-70481DE76C81}><C:\WINDOWS\system32\Mcplxm.dll>  [N/A]
    <{B9A3F6F0-7B1B-4FB8-B743-81FD968D0C63}><C:\WINDOWS\system32\Alff.dll>  [N/A]
    <{63518800-8987-4ADD-962E-926E71212846}><C:\WINDOWS\system32\Okvpjb.dll>  [N/A]
    <{7F16BFB7-A28A-4DFB-A6A1-59B038396840}><C:\WINDOWS\system32\Kfrkrx.dll>  [N/A]
    <{B7C0D325-0D91-438C-809B-E085C507F1A3}><C:\WINDOWS\system32\Iuxkez.dll>  [N/A]
    <{ED5CC319-3AA8-42A5-BDEF-3B434F8EDD69}><C:\WINDOWS\system32\Rywxjv.dll>  [N/A]
    <{EE994066-0BEA-4E25-A0C7-55DACC6DC943}><C:\WINDOWS\system32\Ekxm.dll>  [N/A]
    <{6212930C-0848-4509-9C9D-5C8847904591}><C:\WINDOWS\system32\Uzhqrm.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
    <WinlogonNotify: IntelWireless><C:\Program Files\Intel\Wireless\Bin\LgNotify.dll>  [Intel Corporation]

==================================
启动文件夹
[Adobe Reader Speed Launch]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[Microsoft Office]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [Microsoft Corporation]><N>
[Cyber-shot Viewer 媒体检查工具]
  <C:\Documents and Settings\liang\「开始」菜单\程序\启动\Cyber-shot Viewer 媒体检查工具.lnk --> C:\PROGRA~1\Sony\SONYPI~1\VOLUME~1\SPUVOL~1.EXE [Sony Corporation]><N>
[QQ游戏启动加速程序]
  <C:\Documents and Settings\liang\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> C:\PROGRA~1\Tencent\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>

==================================
gototop
 

<winboot><wscript.exe /E:vbs C:\WINDOWS\boot.ini> [N/A]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
<{F584A094-D920-4010-9EE3-940A4396A4F8}><C:\WINDOWS\system32\Hheiqz.dll> [N/A]
<{3C62C6CB-6D88-460B-AB6A-F8372BDA515F}><C:\WINDOWS\system32\Gnyhg.dll> [N/A]
<{19C2B337-A55F-49AC-9D64-558C91850C03}><C:\WINDOWS\system32\Oefnfa.dll> [N/A]
<{395AECB8-C9F2-4E89-85D9-B0282548EA2F}><C:\WINDOWS\system32\Gyngi.dll> [N/A]
<{331B49D8-8FDD-486D-909D-71423C9B7935}><C:\WINDOWS\system32\Enpmlj.dll> [N/A]
<{E772756B-1C95-4427-B8BE-5A464FBAB241}><C:\WINDOWS\system32\Sivjc.dll> [N/A]
<{25C5AD02-DA3C-4464-B704-E107F22990A2}><C:\WINDOWS\system32\Dxfmx.dll> [N/A]
<{C871091E-1FF2-408E-A85B-B935B23E4748}><C:\WINDOWS\system32\Yxni.dll> [N/A]
<{60748CD7-1076-46DC-84C9-7976F4721E89}><C:\WINDOWS\system32\Kkcwc.dll> [N/A]
<{343BE343-BD8F-4BFF-9914-546DB443E111}><C:\WINDOWS\system32\Mvpp.dll> [N/A]
<{BF0BF363-CF72-402F-95E4-762A433E1E39}><C:\WINDOWS\system32\Araita.dll> [N/A]
<{A6685A0F-143D-4019-A638-DCE165B845AF}><C:\WINDOWS\system32\Oabshi.dll> [N/A]
<{054058EF-6E7A-4D0B-8C17-560883BF6846}><C:\WINDOWS\system32\Qpko.dll> [N/A]
<{B5626087-DFB4-43A5-873D-59F204946663}><C:\WINDOWS\system32\Xceaje.dll> [N/A]
<{77045EE4-BC55-4755-8AC5-ADFB3238DFCF}><C:\WINDOWS\system32\Qipcs.dll> [N/A]
<{E0139903-139E-4FCC-9A96-747397B0D896}><C:\WINDOWS\system32\Qmzwf.dll> [N/A]
<{DAD633F7-E1B4-433D-8733-D9CA4200E8B4}><C:\WINDOWS\system32\Xnpev.dll> [N/A]
<{49DB541D-A9B1-49EA-AEFC-D3D77707AEED}><C:\WINDOWS\system32\Ktqcef.dll> [N/A]
<{2E802E9F-DEA5-4477-8153-27F15BD2C933}><C:\WINDOWS\system32\Nmso.dll> [N/A]
<{B9E4D1CA-6CAF-4E2A-9F79-60A1F2EE1951}><C:\WINDOWS\system32\Ltcv.dll> [N/A]
<{83C77F8D-B379-4793-837F-C71EFAE8ADD0}><C:\WINDOWS\system32\Xlabuh.dll> [N/A]
<{72B7250F-4FB3-4791-863F-E594198F0921}><C:\WINDOWS\system32\Mkavo.dll> [N/A]
<{A6CD8965-EF1B-4C6D-9064-2546986DD5F5}><C:\WINDOWS\system32\Iyup.dll> [N/A]
<{0A9BDF42-4C06-4183-BAC9-D86F0967C9BF}><C:\WINDOWS\system32\Qdspuo.dll> [N/A]
<{0693FAEC-616C-48DF-8755-17ACB64C89F6}><C:\WINDOWS\system32\Mxklr.dll> [N/A]
<{83F0734B-649F-4C70-9D24-70481DE76C81}><C:\WINDOWS\system32\Mcplxm.dll> [N/A]
<{B9A3F6F0-7B1B-4FB8-B743-81FD968D0C63}><C:\WINDOWS\system32\Alff.dll> [N/A]
<{63518800-8987-4ADD-962E-926E71212846}><C:\WINDOWS\system32\Okvpjb.dll> [N/A]
<{7F16BFB7-A28A-4DFB-A6A1-59B038396840}><C:\WINDOWS\system32\Kfrkrx.dll> [N/A]
<{B7C0D325-0D91-438C-809B-E085C507F1A3}><C:\WINDOWS\system32\Iuxkez.dll> [N/A]
<{ED5CC319-3AA8-42A5-BDEF-3B434F8EDD69}><C:\WINDOWS\system32\Rywxjv.dll> [N/A]
<{EE994066-0BEA-4E25-A0C7-55DACC6DC943}><C:\WINDOWS\system32\Ekxm.dll> [N/A]
<{6212930C-0848-4509-9C9D-5C8847904591}><C:\WINDOWS\system32\Uzhqrm.dll> [N/A]
第一页就这么多...楼主的启动项也太多了吧
还有两个不知道是什么
<New.net Startup><rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s> [N/A]
<SunJavaUpdateSched><C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe> [N/A]
gototop
 

可疑启动项目太多
建议把日志发全
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT