瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 灰鸽子的问题,请帮忙!急【求助】

12   1  /  2  页   跳转

灰鸽子的问题,请帮忙!急【求助】

灰鸽子的问题,请帮忙!急【求助】

开机后用HijackThis检测,会出现"C:\Program Files\Internet Explorer\IEXPLORE.EXE"
项.但用瑞星最新本杀毒后,再检测,就没有这项了.
杀毒的结果是:发现病毒.说IEXPLORE.EXE感染了Backdoor.Gpigeon.ugu.已杀,但每次重启系统,又出现这个病毒,真的不知道怎么杀.

瑞星网站的病毒资料又显示:"没有查到与Backdoor.Gpigeon.ugu匹配的病毒资料。"

请帮忙解决,谢谢!
最后编辑2006-01-14 16:13:36
分享到:
gototop
 

请把你的HJ日志贴上来
gototop
 

【回复“卧龙传说”的帖子】
杀毒前:
HijackThis_815汉化版扫描日志 V1.99.1
保存于      10:29:29, 日期 2006-1-12
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\sheng\桌面\4842302005817230232\HijackThis1991zww.exe

O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <meta name="GENERATOR" content="Microsoft FrontPage 5.0">
O1 - Hosts: <meta name="ProgId" content="FrontPage.Editor.Document">
O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=gb2312">
O1 - Hosts: </head>
O1 - Hosts: <body bgcolor="#000000">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <table height="20" cellSpacing="0" cellPadding="0" width="750" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="52" style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: <center>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="752" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n155.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n156.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n157.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n158.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n159.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n160.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img height="60" src="images/n161.jpg" width="80" border="0"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n162.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px"><br>
O1 - Hosts: <img src="images/n163.jpg" border="0" width="80" height="60">
O1 - Hosts: <font size="2" style="font-size: 12px; font-family: 宋体; text-decoration: none" color="#ffffff">
O1 - Hosts:  </font></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </center>
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"><br>
O1 - Hosts: <p align="center">
O1 - Hosts: <font color="#ffff00" size="3" style="font-size: 12px; font-family: 宋体; text-decoration: none">
O1 - Hosts: 由于注册人数过多,显示不正常请刷新本页</font><img src="images/input.gif" width="700" height="80"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/l.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: <td background="images/mobile.gif" height="50" style="font-size: 12px"> </td>
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/r.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [RfwMain] "c:\program files\rising\rfw\rfwmain.exe" -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: (no name) - {e1fc9760-7b95-49cd-80b9-8c9e41017b93} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O23 - NT 服务:  internet systemrundll - Unknown owner - C:\WINDOWS\systemrundll.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

gototop
 

【回复“卧龙传说”的帖子】
杀毒后的:
HijackThis_815汉化版扫描日志 V1.99.1
保存于      10:32:18, 日期 2006-1-12
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\sheng\桌面\4842302005817230232\HijackThis1991zww.exe

O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <meta name="GENERATOR" content="Microsoft FrontPage 5.0">
O1 - Hosts: <meta name="ProgId" content="FrontPage.Editor.Document">
O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=gb2312">
O1 - Hosts: </head>
O1 - Hosts: <body bgcolor="#000000">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <table height="20" cellSpacing="0" cellPadding="0" width="750" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="52" style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: <center>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="752" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n155.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n156.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n157.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n158.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n159.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n160.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img height="60" src="images/n161.jpg" width="80" border="0"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n162.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px"><br>
O1 - Hosts: <img src="images/n163.jpg" border="0" width="80" height="60">
O1 - Hosts: <font size="2" style="font-size: 12px; font-family: 宋体; text-decoration: none" color="#ffffff">
O1 - Hosts:  </font></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </center>
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"><br>
O1 - Hosts: <p align="center">
O1 - Hosts: <font color="#ffff00" size="3" style="font-size: 12px; font-family: 宋体; text-decoration: none">
O1 - Hosts: 由于注册人数过多,显示不正常请刷新本页</font><img src="images/input.gif" width="700" height="80"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/l.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: <td background="images/mobile.gif" height="50" style="font-size: 12px"> </td>
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/r.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [RfwMain] "c:\program files\rising\rfw\rfwmain.exe" -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: (no name) - {e1fc9760-7b95-49cd-80b9-8c9e41017b93} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0B6E50E6-AED7-4408-B40F-1A5A3ACB373F}: NameServer = 202.96.128.68
O23 - NT 服务:  internet systemrundll - Unknown owner - C:\WINDOWS\systemrundll.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

gototop
 

O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <meta name="GENERATOR" content="Microsoft FrontPage 5.0">
O1 - Hosts: <meta name="ProgId" content="FrontPage.Editor.Document">
O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=gb2312">
O1 - Hosts: </head>
O1 - Hosts: <body bgcolor="#000000">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <table height="20" cellSpacing="0" cellPadding="0" width="750" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="52" style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: <center>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="752" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n155.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n156.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n157.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n158.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n159.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n160.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img height="60" src="images/n161.jpg" width="80" border="0"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px">
O1 - Hosts: <img src="images/n162.jpg" border="0" width="80" height="60"> </td>
O1 - Hosts: <td width="125" style="font-size: 12px"><br>
O1 - Hosts: <img src="images/n163.jpg" border="0" width="80" height="60">
O1 - Hosts: <font size="2" style="font-size: 12px; font-family: 宋体; text-decoration: none" color="#ffffff">
O1 - Hosts:  </font></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </center>
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td width="748" height="1" style="font-size: 12px">
O1 - Hosts: <img height="12" src="images/vod.gif" width="750" border="0"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"><br>
O1 - Hosts: <p align="center">
O1 - Hosts: <font color="#ffff00" size="3" style="font-size: 12px; font-family: 宋体; text-decoration: none">
O1 - Hosts: 由于注册人数过多,显示不正常请刷新本页</font><img src="images/input.gif" width="700" height="80"></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="770" align="center" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/l.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: <td background="images/mobile.gif" height="50" style="font-size: 12px"> </td>
O1 - Hosts: <td vAlign="top" width="210" rowSpan="4" style="font-size: 12px">
O1 - Hosts: <table cellSpacing="0" cellPadding="0" width="100%" border="0" style="font-size: 12pt">
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <img src="images/r.jpg" width="198" height="457"></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px"> </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr style="font-size: 12pt">
O1 - Hosts: <td style="font-size: 12px">
O1 - Hosts: <div align="center">
O1 - Hosts: </div>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O23 - NT 服务: internet systemrundll - Unknown owner - C:\WINDOWS\systemrundll.exe
gototop
 

我也中了这个病毒,杀了一星期也没杀掉,实时监控也被此病毒强行关掉了。瑞星病毒库里也没此病毒啊。
gototop
 

【回复“卧龙传说”的帖子】
刚才发错了,现在改好了,请再看看.谢谢
我看了几篇文章,按上面说的查了一下,但在安全模式下只搜索到:mag_hook.dll,其它的都没.还有,我用iceSword查过,也没发现NOTEPAD.EXE.TEP这进程.
下面是ICESWORD的LOG
杀毒前:进程:

System Idle Process
System
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\RavMonD.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\explorer.exe
D:\33\IceSword1[1].12\IceSword\IceSword.exe
C:\Program Files\Rising\Rfw\rfwmain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE



杀毒后:
进程:

System Idle Process
System
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\RavMonD.exe
D:\33\IceSword1[1].12\IceSword\IceSword.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Rising\Rfw\rfwmain.exe

也是差了一个IEXPLORE.EXE
gototop
 

【回复“Qccqcc”的帖子】

顶,自己顶
gototop
 

朋友仔换只木马杀客吧
gototop
 

修复
所有的01项
以及下面这一项:
O23 - NT 服务: internet systemrundll - Unknown owner - C:\WINDOWS\systemrundll.exe

删除systemrundll.exe

在硬盘中搜索systemrundll.dll
systemrundllkey.dll
systemrundll_hook.dll
找到后全部删除

找不到文件请参考图片设置:

附件附件:

下载次数:235
文件类型:image/pjpeg
文件大小:
上传时间:2006-1-12 12:45:01
描述:



gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT