1   1  /  1  页   跳转

中 fuckme 病毒!

中 fuckme 病毒!

此病毒害死我了,老说我虚拟内存太低,怎么办啊?我用瑞星杀毒了一次,发现了trojan病毒,我把带病毒的文件都删了,但重启后过了不久又发现同样的情况,我都想重装系统了,我用Hijackthis扫描后生成的LOG文件如下,麻烦各位高手分析一下,指条明路!


Logfile of HijackThis v1.99.1
Scan saved at 8:10:28, on 2006-5-5
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\PeanutHull3\PhCore.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\rising\Rfw\Rfw.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\Program Files\Internet Explorer\syssmss.exe
C:\WINNT\system32\Rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\FlashGet\flashget.exe
C:\WINNT\system32\taskmg.exe
C:\Documents and Settings\phsoft11\桌面\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\FUCKKFC\FUCKKFC.COM
O2 - BHO: CPub Object - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll (file missing)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [rfw] C:\Program Files\rising\Rfw\Rfw.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [ApacheTomcatMonitor] "C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe" //MS//Tomcat5
O4 - HKLM\..\Run: [supdate2.dll] RUNDLL32.EXE C:\WINNT\system32\supdate2.dll,Run
O4 - HKLM\..\Run: [System] C:\WINNT\system32\taskmg.exe
O4 - HKLM\..\Run: [WinsSystem] C:\Program Files\Internet Explorer\syssmss.exe
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll",ExecFilter solo
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出当前页到超星阅览器(&A) - C:\Program Files\SSREADER36\ss_all.htm
O8 - Extra context menu item: 导出选中部分到超星阅览器(&S) - C:\Program Files\SSREADER36\ss_select.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度--MP3搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度--图片搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度--新闻搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度--歌词搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度--网页搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度--词典搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 百度--贴吧搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O9 - Extra button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DFE6CB1-617D-41BD-9A2B-6B7CA9634D60}: NameServer = 202.96.134.134,202.96.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{4DFE6CB1-617D-41BD-9A2B-6B7CA9634D60}: NameServer = 202.96.134.134,202.96.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{4DFE6CB1-617D-41BD-9A2B-6B7CA9634D60}: NameServer = 202.96.134.134,202.96.128.68
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PeanuthullCore - 广东网域 - C:\Program Files\PeanutHull3\PhCore.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
最后编辑2006-05-05 12:06:25
分享到:
gototop
 

【回复“renarain”的帖子】
C:\Program Files\Internet Explorer\syssmss.exe
C:\WINNT\system32\taskmg.exe
显示隐藏文件。
找到上面两个文件,用WINRAR做成压缩包(解压密码请用virus),将包发到:baohelin@yahoo.com.cn。帮你看看怎么杀。
gototop
 

【回复“baohe”的帖子】
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\FUCKKFC\FUCKKFC.COM

这一项也有问题
gototop
 

O4 - HKLM\..\Run: [supdate2.dll] RUNDLL32.EXE C:\WINNT\system32\supdate2.dll,Run
gototop
 

baohe,我已把邮件发到你的信箱了急盼回复,我现在都想把电脑砸啦!
gototop
 

O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)这项也有问题。
请下载使用 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
www.27814939.ys168.com
gototop
 

在版主没给你答复前,先简单杀一下吧~~(可能会让你好过些,最少不至于砸电脑~)
显示隐藏文件,下载个删除工具,

使用IceSword杀毒的一些基本操作
http://forum.ikaka.com/topic.asp?board=28&artid=7168178

打开 我的电脑》工具》文件夹选项》查看》显示所有文件,不隐藏受保护的操作系统文件》确定


断网,

结束IE,real,雅虎等不必运行的进程
结束RUNDLL32.EXE
C:\WINNT\system32\taskmg.exe
C:\Program Files\Internet Explorer\syssmss.exe

修复下面的项
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\FUCKKFC\FUCKKFC.COM
O4 - HKLM\..\Run: [supdate2.dll] RUNDLL32.EXE C:\WINNT\system32\supdate2.dll,Run
O4 - HKLM\..\Run: [System] C:\WINNT\system32\taskmg.exe
O4 - HKLM\..\Run: [WinsSystem] C:\Program Files\Internet Explorer\syssmss.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing
查找并删除以下文件
(下面可以在IceSword中进行了)
C:\FUCKKFC\FUCKKFC.COM
C:\WINNT\system32\supdate2.dll
C:\WINNT\system32\taskmg.exe
C:\Program Files\Internet Explorer\syssmss.exe
C:\Program.exe (可能还会有Program.dll等)
gototop
 

【回复“renarain”的帖子】
查杀流程:
http://forum.ikaka.com/topic.asp?board=28&artid=8018867

另:C:\FUCKKFC\FUCKKFC.COM——如果能找到,请发过来。
gototop
 

用俺的软件就不会中招了

地址: http://218.6.144.251/kill.zip
gototop
 

baohe,
    我已按你说的做了,现在没有再出现FUCKME现象,非常感谢!是不是我机子还有另一种病毒?存在FUCKKFC中?很奇怪的是,
我在电脑中没有发现FUCKKFC这个目录而且我是在显示所有隐藏的文件和文件夹的情况下搜索的,但在瑞星监控的查杀目标中却有并且还能发现Trojan.PSW.JHonline.dol病毒,删除后重启仍有此病毒存在。

我在安全模式下也没有发现这个目录,真不知道是怎么回事。
此病毒是属于哪种类型?有何危害?应该如何解决?
还请告知,TKS!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT