瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 手动和自动扫分别扫描到:Hack.SQLScan.a和Trojan.VBS.Launcher.A

1   1  /  1  页   跳转

手动和自动扫分别扫描到:Hack.SQLScan.a和Trojan.VBS.Launcher.A

手动和自动扫分别扫描到:Hack.SQLScan.a和Trojan.VBS.Launcher.A

手动和自动分别扫描到病毒名两Hack.SQLScan.a和四个Trojan.VBS.Launcher.A共十六个病毒
文件名 路径
Wmi.exe>>Wmi\SVCHOST.EXE C:\Recycled
Wmi.exe>>Wmi\ip.vbs C:\Recycled
Wmi.exe>>Wmi\Setup.vbs C:\Recycled
Wmi[1].jpg>>wmi\SVCHOST.EXE c:\Documents and Settings
\Administrator\Local settings\
Temporary Internet Files\Content.IE5
\ SJKVMVOB
Wmi[1].jpg>>wmi\ip.vbs 路径同上
Wmi[1].jpg>>wmi\setup.vbs 路径同上
报告日志:
2006-11-29,17:54:57

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<internat.exe><internat.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavMon><C:\Program Files\rising\rav\RavMon.exe> [Beijing Rising Technology Co., Ltd.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<Super Rabbit Desktop Set><E:\magicset785\MagicSet\DS.EXE /Load> [Super Rabbit Software]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINNT\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
[星空极速]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\星空极速.lnk --> C:\PROGRA~1\ChinaNet\VNETCL~1.EXE []><N>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>
[QQ游戏启动加速程序]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> C:\PROGRA~1\Tencent\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>

==================================
服务
[ASP.NET State Service / aspnet_state]
<C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Remote Reader Machine / Remote Reader Machine]
<"C:\WINNT\system32\ssmc.exe"><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[WindowsTimes / WindowsTimes]
<><N/A>
[Portable Media Serial Number Service / WmdmPmSN]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>

==================================
最后编辑2006-12-22 19:18:07
分享到:
gototop
 

浏览器加载项
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINNT\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[InfosecCertInstall Class]
{0EB487C8-E9AC-43A6-8C4C-083999B0622F} <C:\WINNT\Downloaded Program Files\certInStall.dll, >
[AvlPing Control]
{169B0044-1CD6-4EFE-A5D8-AEC69797A953} <C:\WINNT\DOWNLO~1\avlPing.ocx, telepro>
[Malicious Software Removal Tool]
{4B48D5DF-9021-45F7-A240-60304302A215} <C:\WINNT\Downloaded Program Files\WebCleaner.dll, Microsoft Corporation>
[InfoSecNetSign Class]
{62B938C4-4190-4F37-8CF0-A92B0A91CC77} <C:\WINNT\DOWNLO~1\NetSign.dll, Infosec Technologies Co., Ltd.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINNT\system32\muweb.dll, Microsoft Corporation>
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINNT\DOWNLO~1\SUBMIT~1.DLL, >
[CSetLET Class]
{C35D7AE1-0865-4A30-BF07-29FA29324155} <C:\WINNT\DOWNLO~1\GDSetLET.dll, >
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINNT\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
gototop
 

正在运行的进程
[PID: 1016][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[PID: 1096][E:\magicset785\MagicSet\DS.EXE] [Super Rabbit Software, 1.50]
[PID: 1104][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[PID: 1148][C:\Program Files\ChinaNet\VnetClient.exe] [, 2006, 6, 30, 11]
[C:\Program Files\ChinaNet\Communicate.dll] [GDCN, 2006, 2, 15, 1]
[C:\Program Files\ChinaNet\DialModule.dll] [GDCN, 2006, 6, 26, 10]
[C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] [, 2004, 2, 28, 1]
[C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX] [, 2006, 6, 2, 14]
[C:\PROGRA~1\ChinaNet\sign.dll] [0, 2004, 12, 1, 1]
[C:\Program Files\ChinaNet\SysPlug\93d07ada-d3ac-485a-85eb-12ca3cee8375\Vnetsafe114.DLL] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\ADVERT~1.OCX] [, 2005, 10, 13, 1]
[C:\PROGRA~1\ChinaNet\VnetBs.ocx] [, 2004, 11, 18, 1]
[C:\PROGRA~1\ChinaNet\VnetSkin.ocx] [GDDC, 2005, 12, 21, 1]
[C:\PROGRA~1\ChinaNet\DialogStyle.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\BDSearch.ocx] [gdcn, 2005, 12, 22, 1]
[C:\PROGRA~1\ChinaNet\PageFram.ocx] [Workgroup, 2006, 6, 23, 17]
[C:\PROGRA~1\ChinaNet\AccPage.ocx] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\AccountMgr.dll] [, 2006, 6, 20, 16]
[C:\PROGRA~1\ChinaNet\Timer.ocx] [, 2006, 7, 21, 9]
[C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX] [, 2006, 4, 4, 1]
[C:\PROGRA~1\ChinaNet\NEWMES~1.DLL] [, 2006, 7, 4, 16]
[C:\PROGRA~1\ChinaNet\PassCtrl.dll] [GDCN, 2006, 3, 1, 16]
[C:\WINNT\system32\wpcap.dll] [Politecnico di Torino, 3, 0, 0, 18]
[C:\WINNT\system32\pthreadVC.dll] [N/A, N/A]
[C:\WINNT\system32\packet.dll] [Politecnico di Torino, 3, 0, 0, 18]
[C:\PROGRA~1\ChinaNet\PlugPush.dll] [, 2004, 12, 21, 1]
[C:\PROGRA~1\ChinaNet\ALLINT~1.DLL] [, 2006, 7, 19, 14]
[C:\PROGRA~1\ChinaNet\VNETLO~1.OCX] [, 2005, 10, 9, 1]
[C:\PROGRA~1\ChinaNet\StatNum.dll] [, 2006, 3, 1, 1]
[C:\PROGRA~1\ChinaNet\VNETON~1.OCX] [, 2005, 3, 2, 1]
[C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL] [GDCN, 2006, 7, 20, 9]
[C:\PROGRA~1\ChinaNet\VnetOptLog.dll] [ , 2006, 5, 10, 14]
[C:\PROGRA~1\ChinaNet\Favorite.ocx] [, 1, 0, 0, 1]
[C:\PROGRA~1\ChinaNet\DlgSkin.ocx] [, 2005, 11, 14, 1]
[C:\WINNT\system32\Macromed\flash\flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[PID: 1124][C:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 14]
[C:\Program Files\Tencent\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2005, 9, 1, 1]
[C:\Program Files\Tencent\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[C:\Program Files\Tencent\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[C:\WINNT\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\SCCore.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQPet.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\WINNT\system32\Macromed\flash\flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[C:\Program Files\Tencent\QQ\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\Program Files\Tencent\QQ\QQMagicFace.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\Program Files\Tencent\QQ\LongConnection.dll] [tencent, 0, 3, 3, 8]
[C:\Program Files\Tencent\QQ\GroupConnection.dll] [Tencent, 5, 0, 202, 30]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[C:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll] [tencent, 0, 2, 2, 3]
[C:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 141]
[C:\Program Files\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 1, 11]
[C:\Program Files\Tencent\QQ\ShareFiles.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQZip.dll] [tencent, 0, 3, 2, 4]
[PID: 1240][C:\WINNT\system32\SafeSignCertReg.exe] [A.E.T. Europe B.V., 2.0.0.2]
[PID: 1356][C:\Program Files\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 1560][C:\Program Files\rising\rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\rising\rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 1596][C:\WINNT\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3424]
[PID: 1680][C:\WINNT\system32\wscript.exe] [Microsoft Corporation, 5.1.0.4615]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1692][C:\WINNT\system32\wscript.exe] [Microsoft Corporation, 5.1.0.4615]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 272][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINNT\system32\Macromed\flash\flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[PID: 1300][C:\Program Files\WinRAR\WinRAR.exe] [Eugene Roshal, 3.30]
[PID: 1384][E:\杀毒\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]

==================================
文件关联
.TXT Error. [notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [hh.exe %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF Error. [notepad.exe %1]
.VBS Error. [wscript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
gototop
 

朋友,我跟你有同样的情况,主要的原因是wmi.jpg引起的,我曾经用ghost恢复过系统,我的ghost是很久之前做的,那时肯定没毒。但是病毒还会出现,而且从进程来看,是有一个cmd自动执行从网上下载了wmi.jpg的。但是在启动cmd之前的一系列操作我就不知道了,而且启动的源头肯定不在C盘,所以我现在也没办法,只是用PD软件阻止了cmd的运行。我给你发过邮件,希望你能看到这个留言。
gototop
 

【回复“vauvi”的帖子】
谢谢你,我今天才看到。我也不知道怎么搞了
gototop
 

呵呵,好像找到解决方法了,到http://www.microsoft.com/china/technet/security/bulletin/ms06-014.mspx下在对应你系统的补丁,这个病毒是网页木马,并不在你的机子上。是浏览网页时中的,只要打上补丁就可以解决了!你试试!看到信息就用你的邮箱发邮件给我。别人误扰!!!
gototop
 

不过为什么不上网也有那个病毒呢?对了,用卡巴杀的病毒名字是Trojan-Downloader.JS.gen 郁闷
gototop
 


删除启动服务项:

[Remote Reader Machine / Remote Reader Machine]
<"C:\WINNT\system32\ssmc.exe"><N/A>
[WindowsTimes / WindowsTimes]
<><N/A>

安全模式删除:
C:\WINNT\system32\ssmc.exe
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT