瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 18.10.42的瑞星版本居然杀不了这个木马,谁来帮帮我??

1   1  /  1  页   跳转

18.10.42的瑞星版本居然杀不了这个木马,谁来帮帮我??

18.10.42的瑞星版本居然杀不了这个木马,谁来帮帮我??

每次开机或重启后都会出现内存病毒,谁来帮我清除一下.
这是杀出来的内存病毒名Worm.Mail.vbt    我从中毒的机子上复制文件到U盘,然后再到另一台没中毒的机子上杀毒,杀出病毒名是Worm.Mail.Brontok.ac 下面是我重启机子后的日志
Logfile of HijackThis v1.99.1
Scan saved at 17:43:52, on 2006-1-26
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Rising\Rav\Ravmond.exe
D:\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
D:\Rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\conime.exe
E:\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [RavTask] "D:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\bronstab.exe"
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\System32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\zj\Local Settings\Application Data\smss.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Empty.pif = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O11 - Options group: [!CNS]  网络实名
O17 - HKLM\System\CCS\Services\Tcpip\..\{423D0BE1-4BC7-4638-A402-0FC6AAC3FF6D}: NameServer = 10.1.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{423D0BE1-4BC7-4638-A402-0FC6AAC3FF6D}: NameServer = 10.1.1.1
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\Ravmond.exe

最后编辑2006-01-28 09:21:13
分享到:
gototop
 

上面发错了,那是杀毒后的日志,现在发的是没杀毒之前的日志
Logfile of HijackThis v1.99.1
Scan saved at 17:47:02, on 2006-1-26
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Rising\Rav\Ravmond.exe
D:\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
D:\Rising\Rav\RavTask.exe
D:\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\zj\Local Settings\Application Data\winlogon.exe
C:\WINDOWS\System32\conime.exe
C:\Documents and Settings\zj\Local Settings\Application Data\services.exe
C:\Documents and Settings\zj\Local Settings\Application Data\lsass.exe
E:\HijackThis.exe
C:\Documents and Settings\zj\Local Settings\Application Data\inetinfo.exe

F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [RavTask] "D:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\bronstab.exe"
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\System32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\zj\Local Settings\Application Data\smss.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Empty.pif = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O11 - Options group: [!CNS]  网络实名
O17 - HKLM\System\CCS\Services\Tcpip\..\{423D0BE1-4BC7-4638-A402-0FC6AAC3FF6D}: NameServer = 10.1.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{423D0BE1-4BC7-4638-A402-0FC6AAC3FF6D}: NameServer = 10.1.1.1
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\Ravmond.exe

gototop
 

我在线等待各位大侠的指导,谢谢
gototop
 

C:\Documents and Settings\zj\Local Settings\Application Data\winlogon.exe
C:\Documents and Settings\zj\Local Settings\Application Data\services.exe
C:\Documents and Settings\zj\Local Settings\Application Data\lsass.exe
C:\Documents and Settings\zj\Local Settings\Application Data\inetinfo.exe



F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"

O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\bronstab.exe"
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\zj\Local Settings\Application Data\smss.exe"
O4 - Startup: Empty.pif = ?

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

觉得这些有问题
gototop
 

我对日志扫描不太懂,希望大家能教我处理的办法.谢谢
gototop
 

点任务管理器结束进程C:\Documents and Settings\zj\Local Settings\Application Data\winlogon.exe
C:\Documents and Settings\zj\Local Settings\Application Data\services.exe
C:\Documents and Settings\zj\Local Settings\Application Data\lsass.exe
C:\Documents and Settings\zj\Local Settings\Application Data\inetinfo.exe

勾选、修复:
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\bronstab.exe"
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\System32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\zj\Local Settings\Application Data\smss.exe"
O4 - Startup: Empty.pif = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O17 - HKLM\System\CCS\Services\Tcpip\..\{423D0BE1-4BC7-4638-A402-0FC6AAC3FF6D}: NameServer = 10.1.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{423D0BE1-4BC7-4638-A402-0FC6AAC3FF6D}: NameServer = 10.1.1.1
重启,勾选显示所有文件、找到以下路径文件删除:
C:\Documents and Settings\zj\Local Settings\Application Data\winlogon.exe
C:\Documents and Settings\zj\Local Settings\Application Data\services.exe
C:\Documents and Settings\zj\Local Settings\Application Data\lsass.exe
C:\Documents and Settings\zj\Local Settings\Application Data\inetinfo.exe
C:\WINDOWS\eksplorasi.exe
C:\WINDOWS\ShellNew\bronstab.exe
C:\WINDOWS\System32\sti_ci.dll,WiaCreateWizardMenu
C:\WINDOWS\System32\DrvMon.exe
C:\Documents and Settings\zj\Local Settings\Application Data\smss.exe
gototop
 

【回复“天天网”的帖子】现在我就试试,先谢谢这位大侠
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT