瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 狂晕,瑞星居然成了病毒,升级后机器居然启动不了!

12   1  /  2  页   跳转

狂晕,瑞星居然成了病毒,升级后机器居然启动不了!

狂晕,瑞星居然成了病毒,升级后机器居然启动不了!

这是什么毒啊
真的好厉害啊

附件附件:

下载次数:194
文件类型:image/pjpeg
文件大小:
上传时间:2006-11-22 20:00:14
描述:



最后编辑2006-11-22 20:32:46
分享到:
gototop
 

这种病毒的形式就是不断的后台运行IE
然后播放歌曲
gototop
 

0.exe不是好东西.删除,包括注册表相关内容,可能还有其它的.
gototop
 

还有就是在桌面上会有
sfr9s9sf.exe这个文件
太可怕了
gototop
 

这只是临时文件夹里的玩意..

瑞星并无病毒..
gototop
 

楼上的要我把样本传给你不
gototop
 

系统自动运行以上图片中的RISING.EXE
但瑞星根本杀不出
gototop
 

把你现在运行的进程报上来看看.
gototop
 

[smss.exe]
PID = 0x164
CommandLine =
smss.exe
0x48580000
C:\WINDOWS\system32\smss.exe
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
Windows NT Session Manager
2005-05-13 11:41:25

ntdll.dll
0x7c930000
C:\WINDOWS\system32\ntdll.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
NT Layer DLL
2005-05-13 11:32:55




[csrss.exe]
PID = 0x19c
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
csrss.exe
0x4a680000
c:\windows\system32\csrss.exe
5.2.3790.0 (srv03_rtm.030324-2048)
Microsoft Corporation
Client Server Runtime Process
2005-05-13 11:16:02

ntdll.dll
0x7c930000
C:\WINDOWS\system32\ntdll.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
NT Layer DLL
2005-05-13 11:32:55

CSRSRV.dll
0x75950000
C:\WINDOWS\system32\csrsrv.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
Client Server Runtime Process
2005-05-13 11:16:01

basesrv.dll
0x75960000
C:\WINDOWS\system32\basesrv.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
Windows NT BASE API Server DLL
2005-05-13 11:12:17

winsrv.dll
0x75980000
C:\WINDOWS\system32\winsrv.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
Windows Server DLL
2005-05-13 11:47:35

GDI32.dll
0x77bd0000
C:\WINDOWS\system32\gdi32.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
GDI Client DLL
2005-05-13 11:20:48

ADVAPI32.dll
0x77f30000
C:\WINDOWS\system32\advapi32.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
Advanced Windows 32 Base API
2005-05-13 11:10:51

KERNEL32.dll
0x7c800000
C:\WINDOWS\system32\kernel32.dll
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
Microsoft Corporation
Windows NT BASE API Client DLL
2005-05-13 11:25:33
gototop
 

rising.exe 发送 bin59420@yahoo.com.cn 可以给你看看..

但是至少可以确定这不是瑞星的文件..
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT