瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 病毒太多了 有的还杀不掉 高手来拯救 有日志 谢谢

1   1  /  1  页   跳转

病毒太多了 有的还杀不掉 高手来拯救 有日志 谢谢

病毒太多了 有的还杀不掉 高手来拯救 有日志 谢谢

Logfile of HijackThis v1.99.1
Scan saved at 19:48:01, on 2004-4-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\软件\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\软件\Rising\Rav\Ravmond.exe
d:\软件\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\软件\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\ac2f.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
d:\软件\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\rundll32.exe
D:\软件\Rising\Rav\RavTask.exe
D:\软件\Rising\Rav\Ravmon.exe
C:\WINDOWS\pkihisss.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
D:\软件\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
D:\软件\Rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\软件\hijackthis\ha_hijackthis_1991\HijackThis.exe

O1 - Hosts: 61.152.169.246 www.npjxjy.com
O1 - Hosts: 61.152.169.246 quxiuu.com
O1 - Hosts: 61.152.169.246 www.23b.cn
O1 - Hosts: 61.152.169.246 www.baidulink.com
O1 - Hosts: 61.152.169.246 www.ookkw.com
O1 - Hosts: 61.152.169.246 www.97725.com
O1 - Hosts: 61.152.169.246 www.54699.com
O1 - Hosts: 61.152.169.246 www.wu7x.cn
O1 - Hosts: 61.152.169.246 d.qbbd.com
O1 - Hosts: 61.152.169.246 w.qbbd.com
O1 - Hosts: 61.152.169.246 web.77276.com
O1 - Hosts: 61.152.169.246 www.77276.com
O1 - Hosts: 61.152.169.246 www.npjxjy.com
O1 - Hosts: 61.152.169.246 www.baidulink.com
O1 - Hosts: 61.152.169.246 www.ookkw.com
O1 - Hosts: 61.152.169.246 www.wu7x.cn
O1 - Hosts: 61.152.169.246 www.wwwlm.net
O1 - Hosts: 61.152.169.246 dm1.yiall.com
O1 - Hosts: 61.152.169.246 www.my6688.cn
O1 - Hosts: 61.152.169.246 www.union123.com
O1 - Hosts: 61.152.169.246 www.ktan.cn
O1 - Hosts: 61.152.169.246 www.2t2t.cn
O1 - Hosts: 61.152.169.246 www.cq530.com
O1 - Hosts: 61.152.169.246 www.365tc.com
O1 - Hosts: 61.152.169.246 ad.qucha.net
O1 - Hosts: 61.152.169.246 www.tan8.cn
O1 - Hosts: 61.152.169.246 www.itjj.net
O1 - Hosts: 61.152.169.246 www.start188.com
O1 - Hosts: 61.152.169.246 www.at58.cn
O1 - Hosts: 61.152.169.246 union.yxad.com
O1 - Hosts: 61.152.169.246 www.iptan.com
O1 - Hosts: 61.152.169.246 www.ip2008.net
O1 - Hosts: 61.152.169.246 www.yqif.com
O1 - Hosts: 61.152.169.246 www.2t2t.cn
O1 - Hosts: 61.152.169.246 www.688ip.com
O1 - Hosts: 61.152.169.246 www.17tc.com
O1 - Hosts: 61.152.169.246 www1.6tan.com
O1 - Hosts: 61.152.169.246 www2.6tan.com
O1 - Hosts: 61.152.169.246 www.6tan.com
O1 - Hosts: 61.152.169.246 www.zztan.com
O1 - Hosts: 61.152.169.246 www.5tanip.com
O1 - Hosts: 61.152.169.246 www.16tc.com
O1 - Hosts: 61.152.169.246 www.163se.net
O1 - Hosts: 61.152.169.246 www.168080.com
O1 - Hosts: 61.152.169.246 www.baidu8.org
O1 - Hosts: 61.152.169.246 www.qqwei.com
O1 - Hosts: 61.152.169.246 qz.magforum.net
O1 - Hosts: 61.152.169.246 www.nze21.com
O1 - Hosts: 61.152.169.246 www.437799.com
O1 - Hosts: 61.152.169.246 www.168080.com
O1 - Hosts: 61.152.169.246 new2.jixie123.cn
O1 - Hosts: 61.152.169.246 www.18dmm.com
O1 - Hosts: 61.152.169.246 www.souxse.cn
O1 - Hosts: 61.152.169.246 x.vvcyin.com
O1 - Hosts: 61.152.169.246 dm1.yiall.com
O1 - Hosts: 61.152.169.246 www.168080.com
O1 - Hosts: 61.152.169.246 www.nze21.com
O1 - Hosts: 61.152.169.246 www.puma163.com
O1 - Hosts: 61.152.169.246 www.138505.com
O1 - Hosts: 61.152.169.246 www.hyap98.com
O1 - Hosts: 61.152.169.246 x.vvcyin.com
O1 - Hosts: 61.152.169.246 www.puma163.com
O1 - Hosts: 61.152.169.246 www.51liulan.cn
O2 - BHO: Jpeg Class - {4970DA77-DB06-4EB9-AAB5-77AF0CC77310} - C:\WINDOWS\system32\f2dc.dll
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86}? - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\软件\新建文件夹\ex51\file\common\support\msdxm.ocx (file missing)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - HKLM\..\Run: [NvCplDaemon] ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] ; nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] ; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RavTask] "D:\软件\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\软件\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [SsAAD.exe] ; D:\软件\SONY\SsAAD.exe
O4 - HKLM\..\Run: [wallpaper] ; c:\windows\system32\壁纸自动换.exe
O4 - HKLM\..\Run: [mhsa] C:\DOCUME~1\我们仨\LOCALS~1\Temp\mhso.exe
O4 - HKLM\..\Run: [runeip] D:\软件\Rising\KakaToolBar\runiep.exe
O4 - HKLM\..\Run: [pkihisss] C:\WINDOWS\pkihisss.exe /i
O4 - HKLM\..\Run: [tejleck] C:\Program Files\Ringz Studio\tejleck.exe
O4 - HKLM\..\Run: [upxdnd] C:\DOCUME~1\我们仨\LOCALS~1\Temp\upxdnd.exe
O4 - HKLM\..\RunOnce: [KKDelay] D:\软件\Rising\KakaToolBar\RunOnce.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ey7r96su0vv4j] C:\DOCUME~1\我们仨\LOCALS~1\Temp\c0nime.exe
O4 - Global Startup: yhihhf.lnk = C:\Program Files\WinRAR\yhihhfl.exe
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - D:\软件\LSPFix\KuGoo3\InExtend\KuGoo3DownXControl.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Fast Client (fast) - Unknown owner - C:\WINDOWS\system32\ac2f.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\软件\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\软件\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\软件\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\软件\Rising\Rav\Ravmond.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

最后编辑2007-04-23 20:56:05
分享到:
gototop
 

O4 - HKLM\..\Run: [mhsa] C:\DOCUME~1\我们仨\LOCALS~1\Temp\mhso.exe
O4 - HKLM\..\Run: [pkihisss] C:\WINDOWS\pkihisss.exe /i
O4 - HKLM\..\Run: [upxdnd] C:\DOCUME~1\我们仨\LOCALS~1\Temp\upxdnd.exe
O4 - HKCU\..\Run: [ey7r96su0vv4j] C:\DOCUME~1\我们仨\LOCALS~1\Temp\c0nime.exe
O4 - Global Startup: yhihhf.lnk = C:\Program Files\WinRAR\yhihhfl.exe

病毒!
O1 - Hosts: 61.152.169.246 www.npjxjy.com
O1 - Hosts: 61.152.169.246 quxiuu.com
O1 - Hosts: 61.152.169.246 www.23b.cn
O1 - Hosts: 61.152.169.246 www.baidulink.com
O1 - Hosts: 61.152.169.246 www.ookkw.com
O1 - Hosts: 61.152.169.246 www.97725.com
O1 - Hosts: 61.152.169.246 www.54699.com
O1 - Hosts: 61.152.169.246 www.wu7x.cn
O1 - Hosts: 61.152.169.246 d.qbbd.com
O1 - Hosts: 61.152.169.246 w.qbbd.com
O1 - Hosts: 61.152.169.246 web.77276.com
O1 - Hosts: 61.152.169.246 www.77276.com
O1 - Hosts: 61.152.169.246 www.npjxjy.com
O1 - Hosts: 61.152.169.246 www.baidulink.com
O1 - Hosts: 61.152.169.246 www.ookkw.com
O1 - Hosts: 61.152.169.246 www.wu7x.cn
O1 - Hosts: 61.152.169.246 www.wwwlm.net
O1 - Hosts: 61.152.169.246 dm1.yiall.com
O1 - Hosts: 61.152.169.246 www.my6688.cn
O1 - Hosts: 61.152.169.246 www.union123.com
O1 - Hosts: 61.152.169.246 www.ktan.cn
O1 - Hosts: 61.152.169.246 www.2t2t.cn
O1 - Hosts: 61.152.169.246 www.cq530.com
O1 - Hosts: 61.152.169.246 www.365tc.com
O1 - Hosts: 61.152.169.246 ad.qucha.net
O1 - Hosts: 61.152.169.246 www.tan8.cn
O1 - Hosts: 61.152.169.246 www.itjj.net
O1 - Hosts: 61.152.169.246 www.start188.com
O1 - Hosts: 61.152.169.246 www.at58.cn
O1 - Hosts: 61.152.169.246 union.yxad.com
O1 - Hosts: 61.152.169.246 www.iptan.com
O1 - Hosts: 61.152.169.246 www.ip2008.net
O1 - Hosts: 61.152.169.246 www.yqif.com
O1 - Hosts: 61.152.169.246 www.2t2t.cn
O1 - Hosts: 61.152.169.246 www.688ip.com
O1 - Hosts: 61.152.169.246 www.17tc.com
O1 - Hosts: 61.152.169.246 www1.6tan.com
O1 - Hosts: 61.152.169.246 www2.6tan.com
O1 - Hosts: 61.152.169.246 www.6tan.com
O1 - Hosts: 61.152.169.246 www.zztan.com
O1 - Hosts: 61.152.169.246 www.5tanip.com
O1 - Hosts: 61.152.169.246 www.16tc.com
O1 - Hosts: 61.152.169.246 www.163se.net
O1 - Hosts: 61.152.169.246 www.168080.com
O1 - Hosts: 61.152.169.246 www.baidu8.org
O1 - Hosts: 61.152.169.246 www.qqwei.com
O1 - Hosts: 61.152.169.246 qz.magforum.net
O1 - Hosts: 61.152.169.246 www.nze21.com
O1 - Hosts: 61.152.169.246 www.437799.com
O1 - Hosts: 61.152.169.246 www.168080.com
O1 - Hosts: 61.152.169.246 new2.jixie123.cn
O1 - Hosts: 61.152.169.246 www.18dmm.com
O1 - Hosts: 61.152.169.246 www.souxse.cn
O1 - Hosts: 61.152.169.246 x.vvcyin.com
O1 - Hosts: 61.152.169.246 dm1.yiall.com
O1 - Hosts: 61.152.169.246 www.168080.com
O1 - Hosts: 61.152.169.246 www.nze21.com
O1 - Hosts: 61.152.169.246 www.puma163.com
O1 - Hosts: 61.152.169.246 www.138505.com
O1 - Hosts: 61.152.169.246 www.hyap98.com
O1 - Hosts: 61.152.169.246 x.vvcyin.com
O1 - Hosts: 61.152.169.246 www.puma163.com
O1 - Hosts: 61.152.169.246 www.51liulan.cn

用记事本打开hosts文件,删除内容,保存!

附件附件:

下载次数:193
文件类型:image/pjpeg
文件大小:
上传时间:2007-4-23 20:17:50
描述:



gototop
 

C:\DOCUME~1\我们仨\LOCALS~1\Temp\mhso.exe

C:\DOCUME~1\我们仨\LOCALS~1\Temp\upxdnd.exe
C:\DOCUME~1\我们仨\LOCALS~1\Temp\c0nime.exe



=============
        凝逸反毒-自己批量加入病毒样本

http://hi.baidu.com/503165656/blog/item/04336f08458b33940a7b82a5.html
http://hi.baidu.com/503165656/blog/item/d5c2d43673632f300a55a9b1.html

凝逸反毒>服务>病毒库>病毒库>初始化
gototop
 

HJ修复如下:
01
02
O4 - HKLM\..\Run: [mhsa] C:\DOCUME~1\我们仨\LOCALS~1\Temp\mhso.exe
O4 - HKLM\..\Run: [pkihisss] C:\WINDOWS\pkihisss.exe /i
O4 - HKLM\..\Run: [upxdnd] C:\DOCUME~1\我们仨\LOCALS~1\Temp\upxdnd.exe
O4 - HKCU\..\Run: [ey7r96su0vv4j] C:\DOCUME~1\我们仨\LOCALS~1\Temp\c0nime.exe
O4 - Global Startup: yhihhf.lnk = C:\Program Files\WinRAR\yhihhfl.exe
O23 - Service: Fast Client (fast) - Unknown owner - C:\WINDOWS\system32\ac2f.exe
重启电脑安全模式清空: C:\DOCUME~1\我们仨\LOCALS~1\Temp\
删除如下文件:
C:\WINDOWS\pkihisss.exe /i
C:\WINDOWS\system32\ac2f.exe
C:\Program Files\WinRAR\yhihhfl.exe

扫SREng日志贴上来!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT