瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 【讨论】是误杀还是病毒潜伏太深?有日志
中了毒995 - 2008-1-15 13:59:00




昨天睡觉前例行升级瑞星杀毒,第二天起来后发现瑞星历史记录多了50多个查杀记录
之前也不觉得有什么不妥,但突然多了这么多病毒还是吓了我一跳,我不知道是瑞星升级过后把我的文件当成是病毒杀了,还是病毒一早就已经潜伏在我的文件里,谁可以帮我看看?



[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler )


附件: 10037742008115134745.txt
lqqk7 - 2008-1-15 14:03:00
清一下流氓软件,3721、yahoo什么的都卸掉,系统打补丁
中了毒995 - 2008-1-15 14:05:00
在哪下系统载补丁??
303266474 - 2008-1-15 14:06:00
杀软报的病毒的文件名和路径?

下载windows清理助手清理恶意软件
http://www.arswp.com/download/arswp/arswp.rar
中了毒995 - 2008-1-15 14:10:00



lqqk7 - 2008-1-15 14:11:00
用windows update打补丁,或者用卡卡助手的漏洞扫描
中了毒995 - 2008-1-15 14:21:00
瑞星和卡卡的漏洞扫描我都在用啊,卡卡没有扫描到漏洞
lqqk7 - 2008-1-15 14:41:00
如果你能通过正版验证,最好用windows update,不知道卡卡的漏洞库更新了没有
天月来了 - 2008-1-15 14:43:00
从日志这个看,不知道系统文件C:\WINDOWS\system32\ctfmon.exe还是不是系统自己的了,自己去看看文件属性去。
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [N/A]

那些杀软杀出的病毒文件名和路径说说呢。

可能都是在IE缓存里吧。
中了毒995 - 2008-1-15 14:58:00
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
AdWare.HBang.e删除成功2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台cgahap.exe>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.dll>>HBHelper.本机
Trojan.ZSKiller.a需要解压缩后杀毒2008-1-15 3:18快捷方式查杀F:\(D)\浩方对战平台\cga2_cns_yassist.exe>>$PLUGINSDIRwmpns.dll>>6b本机
Trojan.DL.Agent.iwv删除成功2008-1-15 3:36快捷方式查杀F:\新建文件夹 (2)\skesnpmw.dll>>6c本机
Trojan.ZSKiller.a需要解压缩后杀毒2008-1-15 12:55手动查杀F:\(D)\浩方对战平台\cga2_cns_yassist.exe>>$PLUGINSDIRwmpns.dll>>6b本机
中了毒995 - 2008-1-15 15:01:00
查杀的文件太多了,只好发3分1上来
查杀的文件对象多数是浩方的......而且我已经很久米用过了.....
中了毒995 - 2008-1-15 15:03:00
AdWare.HBang.e删除成功2008-1-15 2:42快捷方式查杀D:\Documents and Settings\A yang\Local Settings\Application Data\3721TRQua\AdWare\AdWare.Win32.Hengbang.fhbhelper.dll.malicious>>ce本机
Trojan.ZSKiller.a删除成功2008-1-15 2:51快捷方式查杀D:\Program Files\3721\skesnpmw.dll>>6b本机
Trojan.ZSKiller.a删除成功2008-1-15 2:51快捷方式查杀D:\Program Files\3721\skewmpns.dll>>6b本机
这个也惨遭毒手了......
中了毒995 - 2008-1-15 15:08:00
瑞星和卡卡都是最新版的......
天月来了 - 2008-1-15 15:14:00
有条件,就去重装个系统吧。

那些不对路的文件都删删。

但是重启再杀就不再有这些的话,也可以再用一段时间再说。
中了毒995 - 2008-1-15 15:25:00
重启后再杀毒还查出1一个解压缩杀毒,其他正常
lqqk7 - 2008-1-15 15:34:00
重启后还有的这个需要解压缩的是什么?路径?
中了毒995 - 2008-1-15 15:35:00
也是浩方的文件
Trojan.ZSKiller.a需要解压缩后杀毒2008-1-15 12:55手动查杀F:\(D)\浩方对战平台\cga2_cns_yassist.exe>>$PLUGINSDIRwmpns.dll>>6b本机
天月来了 - 2008-1-15 16:03:00
自己去手工删F:\(D)\浩方对战平台\cga2_cns_yassist.exe

删那个cga2_cns_yassist.exe文件。
网络点卡客服 - 2008-1-15 18:31:00
真的!
很复杂!
哈哈哈哈哈..........
暗之喵喵 - 2008-1-15 23:21:00
尽是运行浩方后出现的病毒!需要解压缩后杀毒楼主参考这两个网站的方法解决!http://forum.ikaka.com/topic.asp?topicClose=1&board=201&artid=8404626
http://forum.ikaka.com/topic.asp?board=117&artid=8410747
1
查看完整版本: 【讨论】是误杀还是病毒潜伏太深?有日志