yueying - 2006-9-3 21:57:00
只要进入任何网络游戏的登陆界面,哪怕是QQ的广告或网络硬盘,都有可能弹出嘟嘟网接着就是一系列realplayer.exe变种木马病毒症状,而且我今天中的是新的变种,我重做了系统没有登陆任何非法网站,系统里也还没有装什么软件,当然瑞星都按好了。只是打开刚下跑跑卡丁车,因为登陆器会连接官方网站新闻,这时候又弹出嘟嘟网,然后又中毒了,主页又被改成了7973,虽然在安全模式下我清除了,但是不知道什么时候还会复发。
没有中毒的朋友,你们是怎么维护电脑的???怎么防止中这个毒啊??难道不上网络游戏或不开QQ???
失去你的日子 - 2006-9-3 22:06:00
顶你下这个问题以前有朋友问过你找找在本站搜下有解决办法
偶都半个月没开QQ了别说网游了 哎
yueying - 2006-9-3 22:24:00
这个7939realplayer.exe病毒简直太恶心了,中了又中,为了提高点网站知名度,为了盗取别人的QQ或游戏号,真卑鄙。
yueying - 2006-9-3 22:24:00
这个7939realplayer.exe病毒简直太恶心了,中了又中,为了提高点网站知名度,为了盗取别人的QQ或游戏号,真卑鄙。
永不断の弦 - 2006-9-3 22:29:00
不会吧,楼主弄份日志上来
yueying - 2006-9-3 22:32:00
刚做的系统,登陆了QQ,自动弹出了正常的广告,接着就出了嘟嘟网,然后就中毒了。郁闷死了,我等明白看看瑞星怎么处理吧。
永不断の弦 - 2006-9-3 22:33:00
这个病毒有变种,变种瑞星周五的病毒库杀不了
yueying - 2006-9-3 22:37:00
是啊,我中的就是变种的Rsvtub.dll
我要放飞 - 2006-9-3 22:38:00
2006-09-03,22:15:34
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<KVFW><C:\Program Files\KVFW\kvfw.exe -silent> [Beijing Jiangmin.]
<KvXP><"C:\Program Files\KV2006\KvXP.kxp" /ScanBoot /ScanSys> [Jiangmin Co.Ltd]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> []
<Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<UpdateManager><"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r> [Sonic Solutions]
<Dell Wireless Manager UI><C:\WINDOWS\System32\WLTRAY> []
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<KvMonXP><"C:\Program Files\KV2006\KVMonXP.kxp" /auto> [Jiangmin Co.Ltd]
<KVautoupdate ><C:\Program Files\KV2006\kvolself.exe /silent> [Jiangmin Co.Ltd]
<Desktop><C:\WINDOWS\System32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll> []
<StatusClient 2.6><C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto> [Hewlett-Packard]
<TomcatStartup 2.5><C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe> [Hewlett-Packard]
<HP Software Update><"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"> [Hewlett-Packard Company]
<Realplayer.exe><C:\WINDOWS\System32\Realplayer.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<DelayRun><C:\WINDOWS\system\d36d0b90.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
<WinlogonNotify: AtiExtEvent><Ati2evxx.dll> [ATI Technologies Inc.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><> []
==================================
启动文件夹
[Hotsync 管理器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Hotsync 管理器.lnk><N>
[Cisco Systems VPN Client]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Cisco Systems VPN Client.lnk><N>
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk><N>
[IE-Bar]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE-Bar.lnk><N>
[Service Manager]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Service Manager.lnk><N>
[INTERNAT]
<C:\Documents and Settings\hyc\「开始」菜单\程序\启动\INTERNAT.lnk><N>
[腾讯QQ]
<C:\Documents and Settings\hyc\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><ATI Technologies Inc.>
[Cisco Systems, Inc. VPN Service / CVPND]
<"C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"><Cisco Systems, Inc.>
[InstallDriver Table Manager / IDriverT]
<C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe><Macrovision Corporation>
[KVSrvXP / KVSrvXP]
<C:\Program Files\KV2006\KVSrvXP.exe /Service><Jiangmin Co. Ltd>
[Pml Driver HPZ12 / Pml Driver HPZ12]
<C:\WINDOWS\System32\HPZipm12.exe><HP>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\Program Files\DeskAdTop\deskipn.dll, >
[FiltrateWebObj Class]
{42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} <C:\Program Files\KV2006\KVBHO.dll, Jiangmin Co.Ltd>
[DriveLetterAccess]
{5CA3D70E-1895-11CF-8E15-001234567890} <C:\WINDOWS\system32\dla\tfswshx.dll, Sonic Solutions>
[BrowseHelper Class]
{80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <C:\Program Files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[&Research]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[江民杀毒工具栏]
{B5A34A93-D538-43A7-8371-864CB6148D12} <C:\Program Files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} <C:\PROGRA~1\Powerise\REAL2A~1\PowerPlr.ocx, Powerise Digital>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[iChatX Object]
{FEEC6798-0E56-4037-829E-FD18E5BADE8C} <C:\WINDOWS\Downloaded Program Files\ichatx.dll, 深圳市东方博雅科技有限公司>
[E&xport to Microsoft Excel]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
我要放飞 - 2006-9-3 22:38:00
[C:\Program Files\KV2006\KVEnhS.dll] <Jiangmin Co., Ltd.><9, 2, 6, 02040>
[C:\Program Files\KV2006\KVEnhJ.dll] <Jiangmin Co.Ltd><9, 1, 0, 50822>
[C:\Program Files\KV2006\KVExtCab.dll] <JiangMin Co. Ltd><9, 2, 0, 50822>
[C:\Program Files\KV2006\KvExtZip.dll] <JiangMin Co Ltd.><9, 2, 0, 50822>
[C:\Program Files\KV2006\KVExtZ.dll] <Jiangmin Co. Ltd><9.2.0.503>
[C:\Program Files\KV2006\KVExtTar.dll] <Jiangmin Co. Ltd><9, 2, 0, 50822>
[C:\Program Files\KV2006\KVExtEml.dll] <Jiangmin Co. Ltd.><9, 2, 6, 07050>
[C:\Program Files\KV2006\lang\KVExtEml0804.lng] <N/A><N/A>
[C:\Program Files\KV2006\KVExtLZH.dll] <JiangMin Co. Ltd.><9, 2, 6, 0316>
[C:\Program Files\KV2006\KvExtRar.dll] <JiangMin Co. Ltd.><9, 2, 6, 04020>
[C:\Program Files\KV2006\KVExtGz.dll] <Jiangmin Co. Ltd><9, 0, 6, 04200>
[C:\Program Files\KV2006\KVEnhK.dll] <Jiangmin Co.Ltd><9, 1, 0, 51209>
[C:\Program Files\KV2006\Fix.dll] <Jiangmin Co.Ltd><9, 2, 6, 07110>
[C:\Program Files\KV2006\KvCkMail.dll] <N/A><9, 0, 6, 619>
[C:\Program Files\KV2006\lang\KvMailRes0804.lng] <N/A><N/A>
[C:\Program Files\KV2006\lang\PrivateCfg0804.lng] <TODO: <Company name>><1.0.0.1>
[PID: 400][C:\WINDOWS\System32\SCardSvr.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 540][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 940][C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe] <N/A><N/A>
[C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\hotspot\jvm.dll] <N/A><N/A>
[C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\hpi.dll] <N/A><N/A>
[C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\verify.dll] <N/A><N/A>
[C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\java.dll] <N/A><N/A>
[C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\zip.dll] <N/A><N/A>
[C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\net.dll] <N/A><N/A>
[C:\WINDOWS\system32\jst.dll] <N/A><N/A>
[C:\WINDOWS\system32\d4channel.dll] <Hewlett-Packard><02.07.60>
[C:\Program Files\KV2006\TrojDie.kxp] <Jiangmin Co.Ltd><9.0.6.0413>
[C:\Program Files\KV2006\UpdateX.dll] <JiangMin Co.Ltd.><9, 0, 5, 831>
[C:\Program Files\KV2006\lang\TrojDie0804.lng] <Jiangmin Co.Ltd><9.0.0.0813>
[C:\Program Files\KV2006\GUIExt.dll] <Jiangmin Co.Ltd><9, 0, 5, 927>
[C:\Program Files\KV2006\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[C:\Program Files\KV2006\PProtect.dll] <Jiangmin Co. Ltd.><9.0.0.921>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[C:\Program Files\DeskAdTop\fshook.dll] <><1, 0, 0, 1>
[C:\Program Files\KV2006\ComUIPS.dll] <Jiangmin Ltd.><9. 5. 5. 20>
[PID: 3280][C:\Program Files\KV2006\KRegEx.exe] <Jiangmin Co.Ltd><9.0.6.210>
[C:\Program Files\KV2006\KRegEx.dll] <Jiangmin Co. Ltd.><9.0.6.0119>
[C:\Program Files\DeskAdTop\fshook.dll] <><1, 0, 0, 1>
[C:\Program Files\KV2006\KRegTrust.dll] <Jiangmin Co. Ltd.><9.0.0.825>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[PID: 3504][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[C:\Program Files\DeskAdTop\fshook.dll] <><1, 0, 0, 1>
[C:\Program Files\KV2006\KvShell.dll] <Jiangmin Co.Ltd><9, 0, 5, 830>
[C:\Program Files\KV2006\UpdateX.dll] <JiangMin Co.Ltd.><9, 0, 5, 831>
[C:\Program Files\KV2006\lang\Kvxp0804.lng] <N/A><N/A>
[C:\Program Files\KV2006\APIImpl.dll] <JiangMin Ltd.><9.0.0.500>
[C:\Program Files\KV2006\GUIExt.dll] <Jiangmin Co.Ltd><9, 0, 5, 927>
[C:\Program Files\KV2006\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.5.2005092300>
[C:\Program Files\KV2006\KVBHO.dll] <Jiangmin Co.Ltd><9.0.6.0113>
[C:\Program Files\KV2006\KVAddrDb.dll] <Jiangmin Co.Ltd><9, 0, 0, 1018>
[C:\WINDOWS\system32\dla\tfswshx.dll] <Sonic Solutions><1.04.08a>
[C:\WINDOWS\System32\tfswapi.dll] <Sonic Solutions><1.04.08a>
[C:\WINDOWS\system32\dla\tfswcres.dll] <Sonic Solutions><1.04.08a>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[PID: 3696][C:\Program Files\KV2006\UIHost.exe] <Jiangmin Co. Ltd><9.2.0.50822>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[C:\Program Files\KV2006\UpdateX.dll] <JiangMin Co.Ltd.><9, 0, 5, 831>
[C:\Program Files\KV2006\ComUI.dll] <Jiangmin Ltd.><9. 0. 0.509>
[C:\Program Files\KV2006\ComUIPS.dll] <Jiangmin Ltd.><9. 5. 5. 20>
[PID: 1904][C:\Program Files\Tencent\TT\TTraveler.exe] <腾讯公司><3.0.0.250>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[C:\Program Files\DeskAdTop\fshook.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] <Adobe Systems, Inc.><9,0,16,0>
[PID: 3056][C:\DOCUME~1\hyc\LOCALS~1\Temp\Rar$EX00.562\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[C:\Program Files\DeskAdTop\fshook.dll] <><1, 0, 0, 1>
[PID: 2924][C:\PROGRA~1\Tencent\TT\TCPlus.exe] <腾讯公司><2.0.0.21>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[C:\Program Files\DeskAdTop\fshook.dll] <><1, 0, 0, 1>
[C:\PROGRA~1\Tencent\TT\TDMANA~1.DLL] <腾讯公司><2.0.0.21>
[PID: 3788][C:\WINDOWS\System32\RunDll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\DOCUME~1\hyc\TEMPLA~1\30b4da9\4.dll] <千橡互联><3, 0, 1, 0>
[C:\Program Files\KV2006\KVHookG.dll] <Jiangmin Co.Ltd><9.0.0.1226>
[C:\Program Files\DeskAdTop\fshook.dll] <><1, 0, 0, 1>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
我要放飞 - 2006-9-3 22:42:00
大家帮忙看看,我中毒好像是你们说的 这个病毒7939realplayer.exe,而且还查出来一种trojan/psw.qqpass.adq.dll
怎么办啊?各位高手帮帮忙吧!非常谢谢!
yueying - 2006-9-3 22:44:00
和你们说话的这功夫,我打开QQ的官方网站又中招了,我晕死,这也太频繁了,幸亏我有7939专杀工具。
yyydy - 2006-9-3 22:52:00
shen a jiu jiu wo ba
© 2000 - 2026 Rising Corp. Ltd.