瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

1   1  /  1  页   跳转

thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

同时查到有IPV6.DLL.V
NVCPL64.DLL.V
WINXP.BMP.V
THUMBS.LNK
YKBDFON.EXE

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; Mozilla/4.0(Compatible Mozilla/4.0(Compatible-EmbeddedWB 14.59 http://bsalsa.com/ EmbeddedWB- 14.59  from: http://bsalsa.com/ )

附件附件:

文件名:SREngLOG.TXT
下载次数:142
文件类型:text/plain
文件大小:
上传时间:2008-4-30 14:35:50
描述:txt

分享到:
gototop
 

回复:thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

[AutoRun]
open=ykbdfon.exe
shell\open=打开(&O)
shell\open\Command=ykbdfon.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=ykbdfon.exe
gototop
 

回复:thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

thumbs.lnk
是图片的东东,不是病毒
gototop
 

回复:thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

IPV6.DLL.V
NVCPL64.DLL.V
WINXP.BMP.V
那这些呢,怎么处理
gototop
 

回复:thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

用xdelbox删除以下文件
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
C:\WINDOWS\system32\IPv6.dll
C:\WINDOWS\system32\WatchClient.exe
C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
sreng 启动项目-》注册表,删除
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe]
    <IFEO[auto.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntldr.exe]
    <IFEO[ntldr.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif]
    <IFEO[pagefile.pif]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe]
    <IFEO[sos.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sxs.exe]
    <IFEO[sxs.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\test.exe]
    <IFEO[test.exe]><AUTOGUARDER GUARDED.>  [N/A]
sreng,启动项目->服务,win32服务应用程序
删除
[VRVWatchServer / VRVWatchServer][Running/Auto Start]
  <"C:\WINDOWS\system32\WatchClient.exe" -service><>
好像图片那个是Thunbs.db
gototop
 

回复:thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

谢谢指教,
gototop
 

回复: thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe]
    <IFEO[auto.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntldr.exe]
    <IFEO[ntldr.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif]
    <IFEO[pagefile.pif]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe]
    <IFEO[sos.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sxs.exe]
    <IFEO[sxs.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\test.exe]
    <IFEO[test.exe]><AUTOGUARDER GUARDED.>  [N/A]


上面这些IFEO项应该是防病毒的,不建议删除
gototop
 

回复:thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

嘻嘻
gototop
 

回复:thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看

回复: thumbs.lnk杀不死,重启又出现,有日志高手帮忙看看
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe]
    <IFEO[auto.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntldr.exe]
    <IFEO[ntldr.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif]
    <IFEO[pagefile.pif]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe]
    <IFEO[sos.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sxs.exe]
    <IFEO[sxs.exe]><AUTOGUARDER GUARDED.>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\test.exe]
    <IFEO[test.exe]><AUTOGUARDER GUARDED.>  [N/A]

上面这些IFEO项应该是防病毒的,不建议删除


那些是免疫病毒软件免疫了产生的,,
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT