瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 “三妻二妖”来破坏我的系统和IE了

123   3  /  3  页   跳转

“三妻二妖”来破坏我的系统和IE了

引用:
【花落花又开的贴子】【回复“地区性”的帖子】主要是C:\WINDOWS\System32\svchsot.exe是个马.把这个压缩加密virus发到我的邮箱rsvirus@163.com注名此贴网址.


...........................

这个早删了

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-9-17 18:36:27
描述:



gototop
 

【回复“地区性”的帖子】汗.你的系统还真是8错,这么多病毒.

不过KV现在反应比较快了.
gototop
 

引用:
【花落花又开的贴子】【回复“地区性”的帖子】汗.你的系统还真是8错,这么多病毒.

不过KV现在反应比较快了.
...........................

还是先告诉我 前面的问题怎么解决把!
gototop
 

我的3721就可以完全卸载,不需要别的工具呀,。
gototop
 

O4 - HKLM\..\Run: [advapi32] RUNDLL32 C:\WINDOWS\Downlo~1\_IS_ISC.DLL,isc
主要是这个导致的

3721不要导出这个问题
gototop
 

引用:
【地区性的贴子】
还是先告诉我 前面的问题怎么解决把!
...........................

再用hijackthis在安全模式下扫个LOG贴上来,那么多东东都乱了...
gototop
 

引用:
【花落花又开的贴子】
再用hijackthis在安全模式下扫个LOG贴上来,那么多东东都乱了...
...........................

可恶!又被装上了雅虎!里面捆一大堆流氓!系统老是蓝屏!
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 20:40:51, on 2005-9-24
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\KAV2005\KWatch.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
E:\KAV2005\KPfwSvc.EXE
E:\KV2005\KVSrvXP.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\联想\联想键盘驱动\TGESrvLogon.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\联想\联想键盘驱动\Ps2Kbdriver.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\KV2005\KVMonXP_2.kxp
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\联想\联想键盘驱动\fastkey.exe
E:\KV2005\TrojDie_2.kxp
C:\WINDOWS\System32\wuauclt.exe
E:\KV2005\KRegEx.exe
C:\WINDOWS\System32\DllHost.exe
D:\***文件夹\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - E:\KV2005\KvShell_2.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - E:\FLASHGET\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - E:\FLASHGET\fgiebar.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - E:\KV2005\KvShell_2.dll
O4 - HKLM\..\Run: [HuaShanTGEKBDPS2] C:\Program Files\联想\联想键盘驱动\Ps2Kbdriver.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KvMonXP] "E:\KV2005\KVMonXP_2.kxp" /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: 使用网际快车下载 - E:\Flashget\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - E:\Flashget\jc_all.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\FLASHGET\flashget.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp_2.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp_2.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp_2.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06F3C78A-0530-4C3B-BA92-CE374B81B612}: NameServer = 218.56.57.58,202.102.128.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C5E431E-177C-4BBE-ABCD-48491BB83D71}: NameServer = 202.96.64.68 219.150.32.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{06F3C78A-0530-4C3B-BA92-CE374B81B612}: NameServer = 218.56.57.58,202.102.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{06F3C78A-0530-4C3B-BA92-CE374B81B612}: NameServer = 218.56.57.58,202.102.128.68
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O20 - AppInit_DLLs: APIHookDll.dll
O20 - Winlogon Notify: ZGNotify - C:\WINDOWS\MyNotification.dll
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Kingsoft Personal Firewall Service (KPfwSvc) - Kingsoft Corporation - E:\KAV2005\KPfwSvc.EXE
O23 - Service: KVSrvXP - JiangMin New Tech Ltd. - E:\KV2005\KVSrvXP.exe
O23 - Service: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft Corporation - E:\KAV2005\KWatch.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TGE CardReader Mgr Host v2 (TGECardReaderMgrHost.2) - Unknown owner - C:\Program Files\联想\联想键盘驱动\TGESrvLogon.exe

gototop
 

【回复“地区性”的帖子】修复:
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O20 - AppInit_DLLs: APIHookDll.dll
O20 - Winlogon Notify: ZGNotify - C:\WINDOWS\MyNotification.dll

雅虎助手可以在控制面版中卸载。

log没什么大问题。
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT