12   1  /  2  页   跳转

严重的中毒事件

严重的中毒事件

打开某网页时,只见任务管理器里的进程数突然狂增……连续出现了1.exe、svocht.exe、ravdm.exe、cdnup.exe等“名毒”,强关不及,在关闭某病毒进程时居然出现了“taskmag.exe内存出错,该程序……read”的提示,任务管理器反而被关了。接下来运行超级兔子ie修复和windows流氓软件清理大师,扫描出若干个流氓程序,按下“一键清理”时,同样出现了“该程序……read”的提示而将软件关掉了。运行icesword倒还可以,但治标不治本。

hijackthis日记

Logfile of HijackThis v1.99.1
Scan saved at 23:35:08, on 2006-9-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\ibmpmsvc.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\System32\QCONSVC.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\windows\Explorer.exe
C:\windows\System32\taskmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Rising\Rav\RsAgent.exe
F:\Downloads\SREng系统调试软件.exe
F:\Downloads\KakaSetup.exe
C:\DOCUME~1\LRF\LOCALS~1\Temp\RavTmp\KKSetup.exe
F:\Downloads\ha_hijackthis_1991\HijackThis.exe

O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - (no file)
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386}? - (no file)
O2 - BHO: (no name) - {F4149F9B-E707-4cc0-917F-C892652B62A3} - (no file)
O2 - BHO: (no name) - {F4149F9B-E707-4cc0-917F-C892652B62A3}? - (no file)
O3 - Toolbar: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - E:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll
O4 - HKLM\..\Run: [EZEJMNAP] ; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] ; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [TP4EX] ; tp4ex.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [MSMSGS] ; ; "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] ; ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\windows\System32\ibmpmsvc.exe
O23 - Service: Network Logon (NetWorkLogon) - Unknown owner - rundll32.exe (file missing)
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - (no file)
O23 - Service: QCONSVC - Lenovo - C:\windows\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe


病毒一条条杀太累
求高手来帮设法迅速恢复系统!
最后编辑2006-09-16 00:59:46
分享到:
gototop
 

O23 - Service: Network Logon (NetWorkLogon) - Unknown owner - rundll32.exe (file missing)
打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索NetWorkLogon删除...

修复
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - (no file)
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386}? - (no file)
O2 - BHO: (no name) - {F4149F9B-E707-4cc0-917F-C892652B62A3} - (no file)
O2 - BHO: (no name) - {F4149F9B-E707-4cc0-917F-C892652B62A3}? - (no file)


其他无异常..
gototop
 

有一项不能修复。另外似乎ravdm还没有清除掉,瑞星仍然无法打开监控
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=6979213  ⒊楼下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
gototop
 

等我马上去弄。
还有,ravdm是怎么杀的了,忘记了。
经过刚才在windows、windows\system32以及c盘下按日期排列,手动删除n多病毒文件后,好象大部分恢复正常,
只有qq的timplatform还有问题,如果没记错,是ravdm弄的吧
gototop
 

2006-09-16,00:38:48

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MSMSGS><; ; "C:\Program Files\Messenger\msmsgs.exe" /background>  []
    <MsnMsgr><; ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <EZEJMNAP><; C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe>  [IBM Corp.]
    <IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [Microsoft Corporation]
    <MSPY2002><; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  []
    <TP4EX><; tp4ex.exe>  [IBM Corporation]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <9><C:\windows\System32\Ravdm.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\windows\SYSTEM32\Userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]

==================================
启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\windows\System32\Ati2evxx.exe><ATI Technologies Inc.>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
  <C:\WINDOWS\System32\drivers\CDAC11BA.EXE><N/A>
[EvtEng / EvtEng]
  <C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[IBM Rapid Restore Ultra Service / IBM Rapid Restore Ultra Service]
  <C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe><>
[IBM PM Service / IBMPMSVC]
  <C:\windows\System32\ibmpmsvc.exe><N/A>
[IBM PSA Access Driver Control / PsaSrv]
  <><N/A>
[QCONSVC / QCONSVC]
  <System32\QCONSVC.EXE><Lenovo>
[RegSrvc / RegSrvc]
  <C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Spectrum24 Event Monitor / S24EventMonitor]
  <C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation>
[IBM KCU Service / TpKmpSVC]
  <C:\WINDOWS\system32\TpKmpSVC.exe><N/A>

==================================
浏览器加载项
[BitComet工具栏]
  {3F1ABCDB-A875-46c1-8345-B72A4567E486} <E:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 724][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 780][\??\C:\windows\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 804][\??\C:\windows\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 848][C:\windows\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 860][C:\windows\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\windows\system32\pwdmon.dll]  <N/A><N/A>
[PID: 1024][C:\windows\System32\ibmpmsvc.exe]  <N/A><N/A>
[PID: 1088][C:\windows\System32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4110>
    [C:\windows\System32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2495>
[PID: 1136][C:\windows\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1228][C:\windows\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\DOCUME~1\LRF\LOCALS~1\Temp\y.dll]  <N/A><N/A>
[PID: 1372][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
[PID: 1432][C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe]  <Intel Corporation ><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
[PID: 1632][C:\windows\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1724][C:\windows\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1912][C:\windows\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
    [C:\windows\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 296][C:\windows\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  <Autodesk><16.0.0.86>
    [C:\DOCUME~1\LRF\LOCALS~1\Temp\y.dll]  <N/A><N/A>
[PID: 588][C:\windows\System32\QCONSVC.EXE]  <Lenovo><3, 8, 1, 0>
[PID: 628][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe]  <Intel Corporation><9, 0, 2, 11>
[PID: 1656][C:\WINDOWS\system32\TpKmpSVC.exe]  <N/A><N/A>
[PID: 280][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 1124][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1668][C:\windows\System32\taskmgr.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 416][C:\Program Files\Tencent\TT\TTraveler.exe]  <腾讯公司><2, 2, 0, 224>
    [C:\WINDOWS\System32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
    [C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  <腾讯公司><1, 1, 0, 5>
    [C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Tencent\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 1184][F:\Downloads\SREng系统调试软件.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\windows\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=8156736
gototop
 

没有搜索到ravdm.exe文件和rinld.sys文件,怎么办?
应该是之前已经给删掉了,但是……重新启动以后监控还是打不开啊
gototop
 

用WINRAR 查找..
gototop
 

winrar没有找到,但是。。用卡卡助手打开explorer模块,发现y.dll文件
是否灰鸽子弄出来的?如何清理
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT