瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 帮帮我~~客服几天也没解决问题,日志以上传

12   1  /  2  页   跳转

帮帮我~~客服几天也没解决问题,日志以上传

帮帮我~~客服几天也没解决问题,日志以上传

双击不能打开盘,右键多了自动播放,auto,第三项才是打开,不能显示隐藏文件夹,开机c盘自动弹出,,在安全模式下,瑞星也查不出问题。好几天了,郁闷死了
最后编辑2006-11-09 16:48:58
分享到:
gototop
 

右键多了自动播放。 有时候开了什么程序会有的》`不理解``(关注中...)
gototop
 

右键 打开 盘..
删除
Autorun.inf
gototop
 

是每个盘都有,双击大不开,只有右键才可以打开
gototop
 

引用:
【mopery的贴子】右键 打开 盘..
删除
Autorun.inf
………………


Autorun.inf是隐藏文件,我现在不能显示隐藏文件件。再说我试过,删了还会有
gototop
 

http://mopery.hits.io/yincang.zip

下载 解压 导入..

然后把 显示隐藏文件删除
Autorun.inf 和一个可疑的 .exe 文件..
gototop
 

系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> WordPad.Document.1 = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"

其它启动项
C:\Autorun.inf
AUTORUN = xiaoshen.exe

D:\Autorun.inf
AUTORUN = xiaoshen.exe

F:\Autorun.inf
AUTORUN = xiaoshen.exe

G:\Autorun.inf
AUTORUN = xiaoshen.exe

H:\Autorun.inf
AUTORUN = xiaoshen.exe

WIN.INI
无信息

SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr




还会出现heng。com。我觉得不是落雪

附件附件:

下载次数:198
文件类型:application/octet-stream
文件大小:
上传时间:2006-11-9 11:28:02
描述:



gototop
 

病毒撒..

不是落雪..

http://mopery.hits.io/sreng2.zip 下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
gototop
 

Autorun.inf 和xiaoshen.exe 文件删了还有,sreng2.zip
不能下载,c盘老是弹出。用autoruns,可以么?
gototop
 

未知家族病毒分析
扫描结果:
无可疑文件


系统活动进程
H:\TDDOWNLOAD\RSDETECT.EXE
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL

C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL

C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAIP.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL

C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\YCLICKON.DLL
C:\WINDOWS\DOWNLO~1\CNSHOOK.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\3721\ALREX.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\PROGRA~1\3721\AUTOLIVE.DLL
C:\PROGRA~1\3721\ALLIVEEX.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPHTB.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YDRAGS~1.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASSIST.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YWIPER.DLL

C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YNOTIFIER.DLL

C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YMENUINFO.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YIEANGEL.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\SHELL\YASMENU.DLL

D:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
D:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
D:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
D:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
D:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
D:\PROGRAM FILES\RISING\RFW\MONDRV.DLL
D:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL

C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\E_FLMAIP.DLL

C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL

D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
D:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
D:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
D:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL

C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\PROGRA~1\3721\AUTOLIVE.DLL
C:\PROGRA~1\3721\NOTIFIER.DLL
C:\PROGRA~1\3721\ALLIVEEX.DLL

C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL

C:\WINDOWS\SYSTEM32\ALG.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\3721\SCRBLOCK.DLL
C:\PROGRA~1\3721\ALREX.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YSCRBLOCK.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\YCLICKON.DLL
C:\WINDOWS\DOWNLO~1\CNSHOOK.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\WINDOWS\DOWNLO~1\CNSHINT.DLL
C:\PROGRA~1\3721\AUTOLIVE.DLL
C:\PROGRA~1\3721\ALLIVEEX.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALIVE.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YALLIVEEX.DLL
C:\WINDOWS\DOWNLO~1\CNSPLUS.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V11.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPHTB.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YANGLING.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQIEHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YDRAGS~1.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YASSIST.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\PROGRA~1\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX

C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\MSAGENT\AGENTSVR.EXE
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\WINDOWS\SYSTEM32\REGSVR32.EXE
C:\PROGRA~1\3721\HELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\YHELPER.DLL
C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YPATCH.DLL
C:\WINDOWS\DOWNLO~1\CNSMIN.DLL
C:\WINDOWS\SYSTEM32\DLLREG.DLL

gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT