瑞星卡卡安全论坛
绿林小匪 - 2007-11-23 23:47:00
题目:急救,中了病毒了,xp.exe / BoBoTurbo.exe ,并感染exe文件。
----------------------------------------
内容:
中了病毒了,惨惨惨,
1。系统每个盘符下都有xp.exe,auto.exe,autorun.inf隐藏文件,我全部删除重新ghost系统后,运行winrar压缩软件,又出现了xp.exe,autorun.inf文件,auto.exe不见了。再次删除xp.exe autorun.inf开机后会自己生成。造成双击盘符无法打开,通过单击右键才可以打开。
2。进程里有BoBoTurbo.exe,在WINNT\system里(我2000系统),结束进程有可以删除,开机后自动出现。
3。运行一些程序,比如压缩软件winrar时,系统会自动缩放一下当前文件夹,并会多出一个文件ani.ani
【autorun.inf】 的内容如下:
[AutoRun]
OPEN=XP.EXE
shellexecute=XP.EXE
shell\打开(&O)\command=XP.EXE
----------------------------------------
我在网上搜索相关信息和专杀工具,没有太多实用的可以彻底解决的,
----------------------------------------
我把xp.exe,auto.exe,autorun.inf,ani.ani四个文件 压缩成bingdu.rar上传给你们。
【大家慎重使用】
请大家帮我解决问题啊。谢谢拉!!!(我最近3次碰到的病毒都是感染exe文件的,真烦人)
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)附件:
80678020071123233623.rar
琼台听雨 - 2007-11-24 0:35:00
建议上传至瑞星
天涯之冰 - 2007-11-24 9:36:00
1 下载运行SREng
下载地址:http://www.kztechs.com/sreng/download.html
2 智能扫描=》扫描=》保存报告
3 把日志中的报告以附件的形式传上来
我记得BoBoTurbo.exe这个文件是一个电影网站的控件(好像是酷点星空的),必须安装才能观看,不是病毒!
天涯之冰 - 2007-11-24 10:04:00
http://hi.baidu.com/newcenturysun/blog/item/99a68a5144aca02742a75b36.html
看看这个吧,版主清新阳光的!
天月来了 - 2007-11-24 13:03:00
晕死,瑞星还不认呢。
天月来了 - 2007-11-24 13:05:00
重新ghost系统后,必须确保不使用其他盘的任何文件,不打开任何磁盘。
立即去用WinRAR打开各盘删除根目录下的文件,但是如果你的GHOST可执行文件和WinRAR这些软件都安装在非系统盘,那都不能用的。
绿林小匪 - 2007-11-24 14:23:00
各位朋友,由于中了病毒,2000系统已经无法上网了,但是可以上qq。
只好进98来上网。
这份日志也是在98系统扫描的,98同样中了毒,但好像没有2000系统多。
日志如下:
[CODE]
2007-11-24,14:06:43
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows 98 SE -
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<internat.exe><internat.exe> [Microsoft Corporation]
<ScanRegistry><C:\WINDOWS\scanregw.exe /autorun> [Microsoft Corporation]
<TaskMonitor><C:\WINDOWS\taskmon.exe> [Microsoft Corporation]
<SystemTray><SysTray.Exe> [Microsoft Corporation]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme> [Microsoft Corporation]
<SoundMan><SOUNDMAN.EXE> [Avance Logic, Inc.]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<nwiz><nwiz.exe /install> [NVIDIA Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme> [Microsoft Corporation]
<SchedulingAgent><mstask.exe> [Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
N/A
==================================
驱动程序
N/A
绿林小匪 - 2007-11-24 14:25:00
==================================
浏览器加载项
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\SYSTEM\MSDXM.OCX, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH9D.OCX, Adobe Systems, Inc.>
==================================
正在运行的进程
[PID: 4294941881][C:\WINDOWS\SYSTEM\CFGMGR32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294962853][C:\WINDOWS\SYSTEM\MSNP32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSNET32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\IENPSTUB.DLL] [Microsoft Corporation, 4.71.0831.1]
[C:\WINDOWS\SYSTEM\MSLOCUSR.DLL] [Microsoft Corporation, 4.72.3110.0]
[C:\WINDOWS\SYSTEM\MPREXE.EXE] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MPRSERV.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294843049][C:\WINDOWS\SYSTEM\MSIDLE.DLL] [Microsoft Corporation, 5.50.4807.2300]
[C:\WINDOWS\SYSTEM\MSTASK.EXE] [Microsoft Corporation, 4.71.1972.1]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3612.1700]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294842553][C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294781445][C:\WINDOWS\SYSTEM\NVDD32.DLL] [NVidia Corporation, 4.13.01.4072]
[C:\WINDOWS\SYSTEM\NVARCH32.DLL] [NVIDIA Corporation, 4.13.01.4072]
[C:\WINDOWS\SYSTEM\DDRAW.DLL] [Microsoft Corporation, 4.08.01.0881]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\DDHELP.EXE] [Microsoft Corporation, 4.08.01.0881]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294803325][C:\WINDOWS\SYSTEM\PSBASE.DLL] [Microsoft Corporation, 5.00.1877.5]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\PSTORERC.DLL] [Microsoft Corporation, 5.00.1877.5]
[C:\WINDOWS\SYSTEM\SOFTPUB.DLL] [Microsoft Corporation, 5.131.1877.4]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\WINTRUST.DLL] [Microsoft Corporation, 5.131.1877.5]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.5]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\IMAGEHLP.DLL] [Microsoft Corporation, 4.00]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\PSTORES.EXE] [Microsoft Corporation, 5.00.1877.3]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294880785][C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\WINDOWS\SYSTEM\THUMBVW.DLL] [Microsoft Corporation, 5.50.4807.2300]
[C:\WINDOWS\SYSTEM\ATL.DLL] [Microsoft Corporation, 3.00.8449]
[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB 文件夹\MSONSEXT.DLL] [, ]
[C:\WINDOWS\SYSTEM\MSHTMLED.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\PROGRAM FILES\WINRAR\RAREXT.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\ACTXPRXY.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSLS31.DLL] [Microsoft Corporation, 3.10.349.0]
[C:\WINDOWS\SYSTEM\IMGUTIL.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\WEBVW.DLL] [Microsoft Corporation, 5.00.0312.0]
[C:\WINDOWS\SYSTEM\JSCRIPT.DLL] [Microsoft Corporation, 5.6.0.6626]
[C:\WINDOWS\SYSTEM\SHDOCLC.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSHTML.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MLANG.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\URLMON.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\BROWSELC.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHFOLDER.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
绿林小匪 - 2007-11-24 14:25:00
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.5]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\LINKINFO.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\SETUPAPI.DLL] [Microsoft Corporation, 5.00.1671.1]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\CFGMGR32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\LZ32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WEBCHECK.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MYDOCS.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\SHD401LC.DLL] [Microsoft Corporation, 5.50.4914.1400]
[C:\WINDOWS\SYSTEM\BROWSEUI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHDOC401.DLL] [Microsoft Corporation, 5.50.4914.1400]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\SHDOCVW.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3612.1700]
[C:\WINDOWS\EXPLORER.EXE] [Microsoft Corporation, 4.72.3110.1]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294860301][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\INTERNAT.EXE] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3612.1700]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294860961][C:\WINDOWS\TASKMON.EXE] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294862781][C:\WINDOWS\SYSTEM\USBUI.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WMI.DLL] [Microsoft Corporation, 5.00.1755.1]
[C:\WINDOWS\SYSTEM\SYSTRAY.EXE] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\BATMETER.DLL] [Microsoft Corporation, 5.00.0910.1900]
[C:\WINDOWS\SYSTEM\POWRPROF.DLL] [Microsoft Corporation, 5.00.0910.1900]
[C:\WINDOWS\SYSTEM\SETUPAPI.DLL] [Microsoft Corporation, 5.00.1671.1]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\CFGMGR32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\LZ32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3612.1700]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294897513][C:\WINDOWS\SOUNDMAN.EXE] [Avance Logic, Inc., 5.0.02]
[C:\WINDOWS\SYSTEM\SETUPAPI.DLL] [Microsoft Corporation, 5.00.1671.1]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\CFGMGR32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\LZ32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3612.1700]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294833001][C:\WINDOWS\SYSTEM\WMIEXE.EXE] [Microsoft Corporation, 5.00.1755.1]
[C:\WINDOWS\SYSTEM\WMICORE.DLL] [Microsoft Corporation, 5.00.1755.1]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294832761][C:\WINDOWS\SYSTEM\MSXML3.DLL] [Microsoft Corporation, 8.30.9926.0]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\INETCPLC.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\PNGFILT.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\DISPEX.DLL] [Microsoft Corporation, 5.6.0.6626]
[C:\WINDOWS\SYSTEM\ACTXPRXY.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\VBSCRIPT.DLL] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\SYSTEM\DXTMSFT.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\DXTRANS.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\ATL.DLL] [Microsoft Corporation, 3.00.8449]
[C:\WINDOWS\SYSTEM\CRTDLL.DLL] [Microsoft Corporation, 3.50]
[C:\WINDOWS\SYSTEM\IEPEERS.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\DDRAWEX.DLL] [Microsoft Corporation, 4.87.00.0700]
[C:\WINDOWS\SYSTEM\DDRAW.DLL] [Microsoft Corporation, 4.08.01.0881]
绿林小匪 - 2007-11-24 14:25:00
[C:\WINDOWS\SYSTEM\NTDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH9D.OCX] [Adobe Systems, Inc., 9,0,47,0]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\WINDOWS\SYSTEM\IMGUTIL.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSHTMLED.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSLS31.DLL] [Microsoft Corporation, 3.10.349.0]
[C:\WINDOWS\SYSTEM\JSCRIPT.DLL] [Microsoft Corporation, 5.6.0.6626]
[C:\WINDOWS\SYSTEM\MSHTML.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\RNR20.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\MSAFD.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WSOCK32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSWSOCK.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WS2_32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WS2HELP.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MLANG.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHDOCLC.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\URLMON.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MYDOCS.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\SHFOLDER.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.5]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB 文件夹\MSONSEXT.DLL] [, ]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\BROWSELC.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\BROWSEUI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3612.1700]
[C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\SHDOCVW.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
[PID: 4294640361][C:\WINDOWS\SYSTEM\WINTRUST.DLL] [Microsoft Corporation, 5.131.1877.5]
[C:\WINDOWS\SYSTEM\URLMON.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSAFD.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\RNR20.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WSOCK32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\MSWSOCK.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHFOLDER.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\RICHED20.DLL] [Microsoft Corporation, 5.0.152.0]
[C:\WINDOWS\SYSTEM\CRTDLL.DLL] [Microsoft Corporation, 3.50]
[C:\MY DOCUMENTS\SRENG2\SRENGPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\SYSTEM\WS2_32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\WININET.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\WS2HELP.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.03.1998]
[C:\WINDOWS\SYSTEM\CRYPT32.DLL] [Microsoft Corporation, 5.131.1877.5]
[C:\WINDOWS\SYSTEM\RPCRT4.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\MSOSS.DLL] [Microsoft Corporation, 5.131.1877.3]
[C:\WINDOWS\SYSTEM\VERSION.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\OLEAUT32.DLL] [Microsoft Corporation, 2.40.4518]
[C:\WINDOWS\SYSTEM\OLEDLG.DLL] [Microsoft Corporation, 1.0]
[C:\WINDOWS\SYSTEM\MSVCRT20.DLL] [Microsoft Corporation, 2.11.000]
[C:\WINDOWS\SYSTEM\OLE32.DLL] [Microsoft Corporation, 4.71.2900]
[C:\WINDOWS\SYSTEM\WINSPOOL.DRV] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\COMDLG32.DLL] [Microsoft Corporation, 4.72.3510.2300]
[C:\WINDOWS\SYSTEM\SHELL32.DLL] [Microsoft Corporation, 4.72.3612.1700]
[C:\WINDOWS\SYSTEM\COMCTL32.DLL] [Microsoft Corporation, 5.81]
[C:\WINDOWS\SYSTEM\IMM32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\SHLWAPI.DLL] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\MSVCRT.DLL] [Microsoft Corporation, 6.00.8397.0]
[C:\WINDOWS\SYSTEM\USER32.DLL] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\GDI32.DLL] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\ADVAPI32.DLL] [Microsoft Corporation, 4.80.1675]
[C:\WINDOWS\SYSTEM\KERNEL32.DLL] [Microsoft Corporation, 4.10.2222]
绿林小匪 - 2007-11-24 14:26:00
==================================
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MS.w95.spi.osp
C:\WINDOWS\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.tcp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.udp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.raw
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.rsvptcp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.rsvpudp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=XP.EXE
shellexecute=XP.EXE
shell\打开(&O)\command=XP.EXE
[D:\]
[AutoRun]
OPEN=XP.EXE
shellexecute=XP.EXE
shell\打开(&O)\command=XP.EXE
[E:\]
[AutoRun]
OPEN=XP.EXE
shellexecute=XP.EXE
shell\打开(&O)\command=XP.EXE
[F:\]
[AutoRun]
OPEN=XP.EXE
shellexecute=XP.EXE
shell\打开(&O)\command=XP.EXE
[G:\]
[AutoRun]
OPEN=XP.EXE
shellexecute=XP.EXE
shell\打开(&O)\command=XP.EXE
[H:\]
[AutoRun]
OPEN=XP.EXE
shellexecute=XP.EXE
shell\打开(&O)\command=XP.EXE
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
shjarthur - 2007-11-24 14:56:00
==================================
服务
N/A
==================================
驱动程序
N/A
这两个都是空的…………
刚处理过中这种病毒的机器……
这个病毒非常可怕,在看了SREng的报告时当时就冒冷汗
我把处理的机器日志贴出来,大家可以参考一下
建议重新安装系统比较好……
安装完后,要全盘扫毒,这个毒感染exe文件
附件:
89054620071124144638.txt
newcenturymoon - 2007-11-24 16:05:00
BoBoTurbo.exe就是logogogo.exe的变种
参考http://hi.baidu.com/newcenturysun/blog/item/99a68a5144aca02742a75b36.html
即可
sady0318 - 2007-11-25 1:00:00
这个病毒也遇到了,怎么才算是完全的清除啊
绿林小匪 - 2007-11-25 23:23:00
我用瑞星2008的20.19.50版本查杀,已经解决问题了,呵呵
1
© 2000 - 2026 Rising Corp. Ltd.