论坛帖子内容              Thread Content
贵论坛有病毒
作者 小青   查看 488   发表时间 2008/6/20 18:10  【论坛浏览】
先来看一下这个点击查看大图jygjyuss
jygjyuss
第一个病毒不必说了吧,我是从贵论坛下载附件时中的.真是没想到附件也会中病毒而不是在网页上!!!!害的我平白5日枉度,实在寒心 第二和第三个就使这次事件的沿伸,花了钱买了番茄花园,杀毒光盘时没毒,安装完后各处看看倒看出两个...............还不知道有没有更多的潜伏着呢.........你们知到我是很信任这里的,希望注意一下 jygjyuss
jygjyuss
浪子回:下载附件最好先扫描!不排除有恶意的人!但你这个不是病毒!破解的软件有时候也会被杀毒软件报警!!!

序号 评论者 共有评论 15   【论坛浏览】  【发表评论】 评论时间
1 看海的猴 附件八成是有人如意上传滴吧 2008/6/20 19:06
2 小青 是版主给我的好哇。。。。。。。。。 2008/6/20 19:54
3 小青 删除病毒时连带删了宽待,搞得我一头雾水 2008/6/20 19:55
4 depressedboy 回复 4楼 小青 的帖子
上传文件到扫描一下:http://www.virustotal.com/zh-cn/

然后下载SRENG,扫描把报告贴上来
2008/6/20 23:24
5 小青

  代码  [Copy]:


2008-06-21,16:43:03

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 3, v.3300 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[Microsoft Corporation]
[(Verified)Microsoft Windows Hardware Compatibility Publisher]
<"C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"> [NVIDIA Corporation]
<"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited]
<"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[(Verified)Microsoft Windows Component Publisher]
[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
[Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Science and Technology Corporation Limited]
<{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
[(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
[]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
%SystemRoot%\System32\hidserv.dll>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe">
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
<"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe">

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]

[ati2mtag / ati2mtag][Running/Manual Start]

[HookCont / HookCont][Running/System Start]
<\SystemRoot\system32\drivers\HookCont.sys>
[HookNtos / HookNtos][Running/System Start]
<\SystemRoot\system32\drivers\HookNtos.sys>
[HookReg / HookReg][Running/System Start]
<\SystemRoot\system32\drivers\HookReg.sys>
[HookSys / HookSys][Running/System Start]
<\SystemRoot\system32\drivers\HookSys.sys>
[IC Plus IP100 10/100 Fast Ethernet Adapter NT Driver / ip100xp][Running/Manual Start]

[nvatabus / nvatabus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nvatabus.sys>
[Service for NVIDIA(R) nForce(TM) Audio Enumerator / nvax][Running/Manual Start]

[NVIDIA Disk Cache Filter Driver / nvcchflt][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nvcchflt.sys>
[Service for NVIDIA(R) nForce(TM) Audio / nvnforce][Running/Manual Start]

[NVIDIA nForce AGP Bus Filter / nv_agp][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nv_agp.sys>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]

[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys>
[Secdrv / Secdrv][Stopped/Manual Start]


==================================
浏览器加载项
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3}
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000}
[查看当前站点排名]


==================================
正在运行的进程
[PID: 336][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 492][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 516][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2034)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[PID: 564][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 576][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2034)]
[PID: 724][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 784][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 876][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.28]
[PID: 892][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 952][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 1004][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[PID: 1216][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-0707)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[PID: 1368][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3300 (xpsp.080125-2028)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[C:\PROGRA~1\Wopti\WOPTIE~1.DLL] [共软网络, 1.0.8.103]
[PID: 1600][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.0.36]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[PID: 1636][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 5.0.0.16]
[C:\Program Files\Rising\AntiSpyware\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[PID: 1660][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-2028)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[PID: 384][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.3300 (xpsp.080125-0707)]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[PID: 1052][C:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 6, 3, 80]
[C:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[C:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[PID: 868][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[PID: 1128][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[PID: 124][C:\DOCUME~1\ADMINI~1.DCC\LOCALS~1\Temp\Rar$EX09.359\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
[C:\WINDOWS\system32\IMSC40W.IME] [Microsoft Corporation, 6.0.0.2524]
[C:\DOCUME~1\ADMINI~1.DCC\LOCALS~1\Temp\Rar$EX09.359\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1 localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1636, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1052, C:\PROGRAM FILES\MAXTHON\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1128, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================



2008/6/21 16:43
6 小青 绝对有问题的。。。。。。。。。。。。


Logfile of HijackThis v1.99.1
Scan saved at 16:45:47, on 2008-6-21
Platform: Windows XP SP3, v.3300 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Rising\AntiSpyware\runiep.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1.DCC\LOCALS~1\Temp\Rar$EX09.359\SREngPS.EXE
C:\DOCUME~1\ADMINI~1.DCC\LOCALS~1\Temp\Rar$EX00.000\PrcView.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1.DCC\LOCALS~1\Temp\Rar$EX05.328\HijackThis.exe

O4 - HKLM\..\Run: [IMSCMIG40W] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [runeip] "C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\Rising\AntiSpyware\RunOnce.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 查看当前站点排名 - http://alexa.chinaz.com/alexa.htm
O9 - Extra button: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - Extra 'Tools' menuitem: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{465E3338-641D-4F05-A53B-6DC2F17D3FB6}: NameServer = 202.109.14.5 202.96.209.133
O20 - AppInit_DLLs: ieprot.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

[ 本帖最后由 小青 于 2008-6-21 16:45 编辑 ]
2008/6/21 16:43
7 depressedboy 日志没有问题,

下载临时文件清理工具
http://www.dodudou.com/down/ATF-Cleaner-cn.exe

下载windows清理助手清理恶意软件
http://www.greendown.cn/soft/4421.html

您的杀软是?
2008/6/21 19:35
8 小青 瑞星。。。。。。。。。。。好像不是很有用,清理助手没发现什么威胁。。零时文件清理软件下不了,那个网页错误500。。。。。。。。。。。

[ 本帖最后由 小青 于 2008-6-22 20:05 编辑 ]
2008/6/22 19:53
9 depressedboy 用迅雷可以下载

或者直接下载附件 ATF-Cleaner-cn.rar
ATF-Cleaner-cn.rar


现在电脑还有什么异常么?
2008/6/22 20:26
10 小青 就是很慢,比原来慢。打开任何东西都慢。。。。 2008/6/22 20:43
 共有评论数 15  每页显示 10
页码 1/2  |<  <<   1 2   >>  >| 
论坛登录信息  
本版热门  
Powered by DiY-Page 5.3.0 © 2005-2008