以下提供4个病毒,感兴趣的可以玩一下,
如下:(4个都是打包的的.RAR文件,放心点)
http://xunway.com/VivianGwen/jason/szsvc.rarhttp://xunway.com/VivianGwen/jason/U.rarhttp://xunway.com/VivianGwen/jason/crsss.rarhttp://xunway.com/VivianGwen/jason/crsrs.rar病毒指向 : W32.Rbot.mx蠕虫病毒
szsvc.rar(207.64K) 下载附件 - 保存到网易网盘
U.rar(210.20K) 下载附件 - 保存到网易网盘
crsss.rar(211.76K) 下载附件 - 保存到网易网盘
crsrs.rar(210.21K) 下载附件 - 保存到网易网盘
系统进程不断的增加,直到死机。
付图:
操作系统:WIN NT 4.0 繁体版
急求各位帮助~~谢谢啦
日志如下:
Logfile of HijackThis v1.99.1
Scan saved at PM 04:55:48, on 2007/3/3
Platform: Windows NT 4 SP6 (WinNT 4.00.1381)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\RpcSs.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolss.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\System32\crsss.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\System32\nddeagnt.exe
C:\WINNT\explorer.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\WINNT\system32\ddhelp.exe
C:\WINNT\System32\Atiptaab.exe
C:\PROGRA~1\NAV\vptray.exe
C:\PROGRA~1\NAV\DefWatch.exe
C:\Program Files\Rising\Rav\RavTray.exe
C:\WINNT\System32\tcpsvcs.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINNT\System32\esserver.exe
C:\WINNT\System32\szsvc.exe
C:\WINNT\System32\crsss.exe
C:\WINNT\System32\internat.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINNT\system32\cba\pds.exe
D:\MSSQL7\Binn\sqlmangr.exe
C:\CCProxy\CCProxy.exe
C:\WINNT\System32\llssrv.exe
d:\MSSQL7\binn\sqlservr.exe
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
c:\winnt\system32\pstores.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\qserver.exe
C:\Program Files\Rising\Rav\RavAgent.exe
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\Rising\Rav\RavAlert.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\Program Files\Rising\Rav\RavUpdate.exe
C:\Program Files\Rising\Rav\RNReport.exe
C:\WINNT\System32\LOCATOR.EXE
C:\PROGRA~1\Symantec\QUARAN~1\Server\ScanExplicit.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\SENS.EXE
C:\WINNT\system32\ntvdm.exe
C:\PROGRA~1\Symantec\QUARAN~1\Server\IcePack.exe
C:\WINNT\system32\ams_ii\hndlrsvc.exe
C:\WINNT\system32\cba\xfr.exe
d:\MSSQL7\binn\sqlagent.exe
C:\WINNT\system32\tapisrv.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\system32\ntvdm.exe
F:\tool\HijackThis.exe
F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\System32\xunleibho_v8.dll
O3 - Toolbar: Μ诀(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O13 - WWW. Prefix: http://
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = cnned
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = cnned
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 202.96.128.166 202.96.128.143 202.96.128.68
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = cnned
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 202.96.128.166 202.96.128.143 202.96.128.68
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 202.96.128.166 202.96.128.143 202.96.128.68
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NAV\DefWatch.exe
O23 - Service: Symantec Quarantine Agent (IcePack) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\IcePack.exe
O23 - Service: Intel Alert Handler - IntelR Corporation - C:\WINNT\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel File Transfer - IntelR Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - IntelR Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Symantec AntiVirus 狝竟 (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NAV\Rtvscan.exe
O23 - Service: Symantec System Center 穓碝狝叭 (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: 辽臟いァ筳瞒┮ (qserver) - Symantec Corporation - C:\PROGRA~1\Symantec\QUARAN~1\Server\qserver.exe
O23 - Service: RavAgent - 风琍 - C:\Program Files\Rising\Rav\RavAgent.exe
O23 - Service: Rav Net Alert (RavAlert) - 风琍м祇甶Τそ - C:\Program Files\Rising\Rav\RavAlert.exe
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: RavUpdate - Unknown owner - C:\Program Files\Rising\Rav\RavUpdate.exe" (file missing)
O23 - Service: RNReport - 风琍м祇甶Τそ - C:\Program Files\Rising\Rav\RNReport.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Symantec Quarantine Scanner (ScanExplicit) - IBM Corp. - C:\PROGRA~1\Symantec\QUARAN~1\Server\ScanExplicit.exe
O23 - Service: WmDmPsp - Unknown owner - C:\WINNT\system32\sysdtc32.exe (file missing)