查看: 4635|回复: 13
收起左侧

[已解决] 请大家帮我看下SREngLOG.log,我中的是auto病毒和修改时间病毒

[复制链接]
贝贝
发表于 2007-12-8 12:13:42 | 显示全部楼层 |阅读模式
这2个礼拜给这病毒折磨死了,起初不了解,以为格了重装系统就没事了,这也是听我哥哥说地,新装了系统没过多久,

又发现不对劲了,系统的时间又变成了2005年- -|||,卡巴起不了作用,就算手动更改了时间用卡巴查杀,根本查不出毒,

后来才知道auto病毒会全盘感染,还带病毒下载器......这世界上为什么就有些无聊人士喜欢惟恐天下不乱呢,无语~

拜托大家帮我看看,论文和作业到现在还没办法提交,拜托大家帮我看看,谢谢

通过几天的查杀,还是有好多不懂的地方,请大家赐教,病毒是用瑞星在线查出来, 病毒1-1副本.jpg
病毒2-1副本.jpg
后来我用360的专杀工具killer_autorun.exe清除了,再用瑞星查了边,没查出来...按论坛提示的用SREng查了下,说我进

程有些问题,毕竟我不是特别专研这方面的,根本就看不懂,也不知道怎么修改,所以直接把我的进程SREngLOG.log传

上来,请大家帮我看下,如何修改
  1. 2007-12-06,22:58:08
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18.     <bgswitch><; C:\WINDOWS\system32\bgswitch.exe>  []
  19. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  20.     <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe">  [(Verified)Kaspersky Lab]
  21.     <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Publisher]
  22.     <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
  23.     <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  24.     <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  25.     <nwiz><; nwiz.exe /install>  []
  26.     <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
  27.     <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
  28.     <SoundMan><; SOUNDMAN.EXE>  [(Verified)Microsoft Windows Publisher]
  29.     <360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start>  [奇虎网]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  31.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  32.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  33.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  35.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [(Verified)Kaspersky Lab]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  37.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  39.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  41.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  43.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  45.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  47.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  49.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  51.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  52. ==================================
  53. 启动文件夹
  54. N/A
  55. ==================================
  56. 服务
  57. [Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  58.   <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
  59. [卡巴斯基互联网安全套装 7.0 / AVP][Running/Auto Start]
  60.   <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r><Kaspersky Lab>
  61. [Contrl Center of Storm Media / ccosm][Running/Auto Start]
  62.   <C:\Program Files\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
  63. [Human Interface Device Access / HidServ][Stopped/Disabled]
  64.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  65. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  66.   <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
  67. ==================================
  68. 驱动程序
  69. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  70.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  71. [D-Link DFE-528TX PCI Adapter NT Driver / DLKRTL][Running/Manual Start]
  72.   <system32\DRIVERS\DLKRTL.SYS><D-Link Corporation>
  73. [kl1 / kl1][Running/Boot Start]
  74.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  75. [klif / klif][Running/System Start]
  76.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  77. [Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start]
  78.   <system32\DRIVERS\klim5.sys><Kaspersky Lab>
  79. [nv / nv][Running/Manual Start]
  80.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  81. [Padus ASPI Shell / pfc][Running/Manual Start]
  82.   <system32\drivers\pfc.sys><Padus, Inc.>
  83. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  84.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  85. [WAN Miniport (PPP over Ethernet Protocol) / RMSPPPOE][Running/Manual Start]
  86.   <system32\DRIVERS\RMSPPPOE.SYS><Robert Schlabbach>
  87. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  88.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  89. [Secdrv / Secdrv][Stopped/Manual Start]
  90.   <system32\DRIVERS\secdrv.sys><N/A>
  91. ==================================
  92. 浏览器加载项
  93. [ThunderAtOnce Class]
  94.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, N/A>
  95. [FGCatchUrl]
  96.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch_1.dll, www.flashget.com>
  97. [SafeMon Class]
  98.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
  99. [FlashGet GetFlash Class]
  100.   {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
  101. [Web 反病毒统计]
  102.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll, Kaspersky Lab>
  103. [番茄花园]
  104.   {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
  105. [信息检索(&R)]
  106.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  107. [快车]
  108.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\FlashGet.exe, FlashGet.com>
  109. [Messenger]
  110.   {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
  111. [CKAVWebScan Object]
  112.   {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll, Kaspersky Lab>
  113. [Shockwave Flash Object]
  114.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
  115. [Rising Web Scan Object]
  116.   {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
  117. [ThunderAtOnce Class]
  118.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, N/A>
  119. [CKAVWebScan Object]
  120.   {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll, Kaspersky Lab>
  121. [Windows Media Player]
  122.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  123. [FGCatchUrl]
  124.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch_1.dll, www.flashget.com>
  125. [Thunder Agent Class]
  126.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, N/A>
  127. [Shell Name Space]
  128.   {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
  129. [CKAVReportCtrl Object]
  130.   {6117669B-8C2D-41FA-A6D9-9E484B999CF0} <C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll, Kaspersky Lab>
  131. [XMP Class]
  132.   {6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
  133. [XDRM]
  134.   {693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
  135. [Windows Media Player]
  136.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  137. [360SafeLive]
  138.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
  139. [RMGetLicense Class]
  140.   {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
  141. [SearchAssistantOC]
  142.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  143. [SafeMon Class]
  144.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
  145. [RDS.DataSpace]
  146.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  147. [Shockwave Flash Object]
  148.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
  149. [Rising Web Scan Object]
  150.   {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
  151. [FlashGet GetFlash Class]
  152.   {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
  153. [XPPlayer Class]
  154.   {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder>
  155. [FGAutoLive]
  156.   {F90D830D-C175-4bbe-82C7-FF94669A4C42} <C:\Program Files\FlashGet\fgupdate.dll, www.flashget.com>
  157. [FGCatchUrl]
  158.   {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <C:\Program Files\FlashGet\jccatch_1.dll, www.flashget.com>
  159. [&使用BitComet下载]
  160.   <res://E:\BitComet_0.96\BitComet.exe/AddLink.htm, N/A>
  161. [&使用BitComet下载全部链接]
  162.   <res://E:\BitComet_0.96\BitComet.exe/AddAllLink.htm, N/A>
  163. [&使用BitComet下载本页视频]
  164.   <res://E:\BitComet_0.96\BitComet.exe/AddVideo.htm, N/A>
  165. [&使用快车(FlashGet)下载]
  166.   <C:\Program Files\FlashGet\jc_link.htm, N/A>
  167. [&使用快车(FlashGet)下载全部链接]
  168.   <C:\Program Files\FlashGet\jc_all.htm, N/A>
  169. [导出到 Microsoft Office Excel(&X)]
  170.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  171. [添加到反广告条]
  172.   <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm, N/A>
  173. ==================================
  174. 正在运行的进程
  175. [PID: 848 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  176. [PID: 908 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  177. [PID: 932 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  178.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  179.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 7.0.0.125]
  180. [PID: 976 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  181. [PID: 988 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  182.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
  183.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  184. [PID: 1152 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  185. [PID: 1224 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  186.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
  187. [PID: 1348 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  188.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  189.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll]  [Kaspersky Lab, 7.0.0.125]
  190.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
  191. [PID: 1396 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  192.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  193. [PID: 1456 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  194.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  195. [PID: 1780 / kurama][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  196.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  197.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll]  [Kaspersky Lab, 7.0.0.125]
  198.     [C:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
  199.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll]  [Kaspersky Lab, 7.0.0.125]
  200.     [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9371]
  201.     [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9371]
  202.     [C:\WINDOWS\system32\nvapi.dll]  [N/A, ]
  203.     [C:\WINDOWS\system32\nvshell.dll]  [, ]
  204.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  205.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ShellEx.dll]  [Kaspersky Lab, 7.0.0.125]
  206.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
  207.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
  208. [PID: 1852 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  209.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
  210.     [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
  211.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
  212. [PID: 236 / kurama][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  213. [PID: 340 / SYSTEM][C:\Program Files\StormII\stormliv.exe]  [北京暴风网际科技有限公司, 3, 7, 11, 26]
  214.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
  215.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  216. [PID: 420 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.9371]
  217.     [C:\WINDOWS\system32\nvapi.dll]  [N/A, ]
  218. [PID: 516 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
  219. [PID: 1296 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  220. [PID: 568 / kurama][E:\Downloads\software\查杀病毒工具包\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  221.     [E:\Downloads\software\查杀病毒工具包\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  222.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.125]
  223.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll]  [Kaspersky Lab, 7.0.0.125]
  224.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.125]
  225. [PID: 2748 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  226. ==================================
  227. 文件关联
  228. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  229. .EXE  OK. ["%1" %*]
  230. .COM  OK. ["%1" %*]
  231. .PIF  OK. ["%1" %*]
  232. .REG  OK. [regedit.exe "%1"]
  233. .BAT  OK. ["%1" %*]
  234. .SCR  OK. ["%1" /S]
  235. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  236. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  237. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  238. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  239. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  240. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  241. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  242. ==================================
  243. Winsock 提供者
  244. N/A
  245. ==================================
  246. Autorun.inf
  247. N/A
  248. ==================================
  249. HOSTS 文件
  250. 127.0.0.1       localhost
  251. 0.0.0.0 www.balldu.com
  252. ==================================
  253. 进程特权扫描
  254. N/A
  255. ==================================
  256. API HOOK
  257. RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  258. RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  259. RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  260. RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  261. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  262. ==================================
  263. 隐藏进程
  264. N/A
  265. ==================================
复制代码

[ 本帖最后由 贝贝 于 2007-12-11 21:14 编辑 ]
贝贝
 楼主| 发表于 2007-12-8 12:50:09 | 显示全部楼层
今天提示遭到攻击

2007-12-8 10:49:47        Intrusion.Win.Messenger.exploit! 攻击者IP地址: 218.80.121.234. 协议/服务: UDP 在本地端口135. 时间: 2007-12-8 10:49:47

是不是还没清理干净?
haol
发表于 2007-12-8 13:09:02 | 显示全部楼层
看了一下沒有發現問題
{
ed73ba8f.dll沒有出現在log裡
而Autorun.inf沒有東西
log也沒有可疑程式
}

Intrusion.Win.Messenger.exploit!這個是自動攻擊,非特定對象

[ 本帖最后由 haol 于 2007-12-8 13:15 编辑 ]
sifang
发表于 2007-12-8 13:16:37 | 显示全部楼层
同楼上,没看出什么问题。
贝贝
 楼主| 发表于 2007-12-8 13:28:10 | 显示全部楼层
请教下
API HOOK
RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
是关于什么的,为什么说RVA错误
haol
发表于 2007-12-8 13:59:51 | 显示全部楼层

回复 5楼 贝贝 的帖子

klif.sys ( 這是卡巴的核心驅動)
贝贝
 楼主| 发表于 2007-12-8 14:05:58 | 显示全部楼层
谢谢了,以后要多多学习

终于可以放心交作业去了

[ 本帖最后由 贝贝 于 2007-12-8 14:08 编辑 ]
haol
发表于 2007-12-8 14:12:19 | 显示全部楼层
另外關於System Repair Engineer API HOOK检测
可參考...
http://www.kztechs.com/sreng/help2/apihook.htm
packet
发表于 2007-12-8 20:45:39 | 显示全部楼层
RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
这是卡巴斯基安装的,正常
kyotoair
头像被屏蔽
发表于 2007-12-8 22:48:00 | 显示全部楼层
原帖由 贝贝 于 2007-12-8 12:13 发表
这2个礼拜给这病毒折磨死了,起初不了解,以为格了重装系统就没事了,这也是听我哥哥说地,新装了系统没过多久,

又发现不对劲了,系统的时间又变成了2005年- -|||,卡巴起不了作用,就算手动更改了时间用卡巴查杀 ...




太过于巧合了些,今天下午帮室友杀毒,他的情况跟你一模一样,时间是2005年12月8号,我改成2007,不过一会就又改回来了。月日时分秒都对,就是年始终是2005。

我用360的产品,包括那个防止时间修改的工具,根本不行,一打开就关闭。

最后用windows清理助手轻松搞定。。。
从此,我就在他们心中成了安全专家,the safety professor......      

[ 本帖最后由 kyotoair 于 2007-12-8 22:50 编辑 ]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-3-19 17:33 , Processed in 0.138651 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表