斑竹大大、过路牛人高手,您们好!
小弟我还是.exe病毒的问题,没有彻底的解决,给工作和上网都带来极大的不便!
我是怨恨这个病毒了!这个病毒的作者乐了!NND~KAO!
难道没有更好的盾来抵挡他么?难道我们这里没有更好的人来抵挡它么?我不信!我还是相信我们这里有
高手来抵挡它的,因为我们这里人心团结、人才济济!
病毒的截图好不容易弄到(我弄到后不到一分钟就资源占用100%,就是其他程序打不开了),也已经一
起附上,希望各位大大过目帮忙。
我在附加讲一下症状,现在一出现这个对话框后,用咔吧提示删除后好像没有什么问题,在其他程序使用
过程中(就是其他程序操作,如上网、BT下载等)没有出现问题,不会占用资源100%的情况,但是如果
离开,就是不操作,或者挂着BT在那里下载的话,第二天或者下午来一看,基本都会出现资源100%的情
况,还不能正常关机,我只能按机箱电源按钮重新启动。
还有,这个.exe是不是附带那个eraseme病毒一起来得?好像是(本人是菜鸟,要不然不会苦苦要求各位
大大了),因为出现这个咔吧拦截.exe后删除不久,多半回出现咔吧拦截提示eraseme病毒的,记得我也
发过这么个求助贴,就是斑竹提示的一个帖子:
http://bbs.kafan.cn/viewthread.phptid=69776&extra=page%3D2
我也认真拜读,但是我想问的是,怎么样才知道那个信息?就是那个病毒的子级进程信息从而确定那个病
毒从219.217.81.101的1917端口下载 eraseme_01364.exe 这个文件(也许我的机子不是从这个地址下的
),咔吧可以做到么?如何操作?谢谢~顺便问一下,SSM也是杀毒软件么?
我该怎么办呀?
附带一个SREngLOG的扫描报告:
---------------------------------------------------------------------------------------
- 2007-04-08,18:26:21
- System Repair Engineer 2.4.12.806
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <load><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky
- Lab]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows XP Publisher]
- <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows XP
- Publisher]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows XP Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
- <WinlogonNotify: klogon><C:\WINDOWS\System32\klogon.dll> [Kaspersky Lab]
- ==================================
- 启动文件夹
- [QQ游戏启动加速程序]
- <C:\Documents and Settings\mai\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk -->
- C:\PROGRA~1\Tencent\QQGAME\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
- ==================================
- 服务
- [Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
- <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe
- Systems>
- [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
- <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe -r><Kaspersky Lab>
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [NVIDIA Display Driver Service / NVSvc][Stopped/Disabled]
- <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
- ==================================
- 驱动程序
- [atksgt / atksgt][Running/Auto Start]
- <System32\DRIVERS\atksgt.sys><N/A>
- [C-Media High Definition Audio Interface / cmudax][Running/Manual Start]
- <system32\drivers\cmudax.sys><C-Media Inc.>
- [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
- <System32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
- [gwiopm / gwiopm][Stopped/Manual Start]
- <\??\C:\Program Files\Wom\gwiopm.sys><N/A>
- [Microsoft 用于 High Definition Audio 服务的 UAA 功能驱动程序 / HdAudAddService]
- [Stopped/Manual Start]
- <system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
- [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
- <System32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
- [kl1 / kl1][Running/Boot Start]
- <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
- [klif / klif][Running/System Start]
- <\??\C:\WINDOWS\System32\drivers\klif.sys><Kaspersky Lab>
- [lirsgt / lirsgt][Running/Auto Start]
- <System32\DRIVERS\lirsgt.sys><N/A>
- [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start]
- <System32\DRIVERS\ASACPI.sys><>
- [npkcrypt / npkcrypt][Running/Auto Start]
- <\??\C:\Program Files\ViYaQQ\npkcrypt.sys><INCA Internet Co., Ltd.>
- [nv / nv][Running/Manual Start]
- <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver / rtl8029][Running/Manual Start]
- <System32\DRIVERS\RTL8029.SYS><Realtek Semiconductor Corporation>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <System32\DRIVERS\secdrv.sys><N/A>
- [NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual
- Start]
- <System32\DRIVERS\yk51x86.sys><Marvell>
- ==================================
- 浏览器加载项
- [Web反病毒保护]
- {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-
- Virus 6.0\scieplugin.dll, Kaspersky Lab>
- [信息检索(&R)]
- {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL,
- Microsoft Corporation>
- [@shdoclc.dll,-866]
- {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
- [电台(&R)]
- {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft
- Corporation>
- [上传到QQ网络硬盘]
- <, N/A>
- [使用脱兔下载]
- <C:\Program Files\Tuotu\TT_one.htm, N/A>
- [使用脱兔下载全部链接]
- <C:\Program Files\Tuotu\TT_all.htm, N/A>
- [导出到 Microsoft Office Excel(&X)]
- <res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
- [添加到QQ自定义面板]
- <, N/A>
- [添加到QQ表情]
- <, N/A>
- [用QQ彩信发送该图片]
- <, N/A>
- ==================================
- 正在运行的进程
- [PID: 708][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106
- (xpsp1.020828-1920)]
- [PID: 788][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0
- (xpclient.010817-1148)]
- [PID: 812][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106
- (xpsp1.020828-1920)]
- [C:\WINDOWS\System32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
- [C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-
- 1148)]
- [C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-
- 1148)]
- [PID: 856][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0
- (xpclient.010817-1148)]
- [PID: 868][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106
- (xpsp1.020828-1920)]
- [PID: 1044][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0
- (xpclient.010817-1148)]
- [PID: 1236][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0
- (xpclient.010817-1148)]
- [PID: 1444][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0
- (xpclient.010817-1148)]
- [PID: 1480][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0
- (xpclient.010817-1148)]
- [PID: 1628][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0
- (XPClient.010817-1148)]
- [C:\WINDOWS\System32\adimon.dll] [Autodesk, Inc., 3,0,14,176]
- [C:\WINDOWS\system32\heidi3.dll] [Autodesk, Inc., 3,0,14,176]
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation,
- 11.3.1897.0]
- [PID: 2032][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-
- 1920)]
- [C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-
- 1148)]
- [C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-
- 1148)]
- [D:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation,
- 11.0.5510]
- [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll] [Kaspersky Lab,
- 6.0.0.299]
- [PID: 680][C:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 9, 30]
- [C:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
- [C:\WINDOWS\System32\odbcbcp.dll] [Microsoft Corporation, 2000.081.9030.00]
- [C:\WINDOWS\System32\mscoree.dll] [Microsoft Corporation, 2.0.50727.42 (RTM.050727-
- 4200)]
- [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\perfcounter.dll] [Microsoft Corporation,
- 2.0.50727.42 (RTM.050727-4200)]
- [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll] [Microsoft Corporation,
- 2.0.50727.42 (RTM.050727-4200)]
- [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CorperfmonExt.dll] [Microsoft
- Corporation, 2.0.50727.42 (RTM.050727-4200)]
- [C:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
- [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll] [Microsoft Corporation,
- 2.0.50727.42 (RTM.050727-4200)]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] [Kaspersky Lab,
- 1.0.6.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] [Kaspersky Lab,
- 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll] [Kaspersky Lab,
- 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] [Kaspersky Lab,
- 6.0.0.299]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] [Kaspersky Lab,
- 6.0.0.304]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] [Kaspersky Lab,
- 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] [Kaspersky Lab,
- 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] [Kaspersky Lab,
- 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl] [Kaspersky Lab,
- 6.0.0.299]
- [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl] [Kaspersky Lab,
- 6.0.0.299]
- [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
- [C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-
- 1148)]
- [C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-
- 1148)]
- [PID: 2352][C:\sreng2\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
- ==================================
- 文件关联
- N/A
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- API HOOK
- RVA 错误: LoadLibraryA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF4C69B25)
- RVA 错误: LoadLibraryExA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF4C69D67)
- RVA 错误: LoadLibraryExW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF4C69F0B)
- RVA 错误: LoadLibraryW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF4C69C49)
- RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: Dest Addr: 0xF4C69E8F)
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码
-------------------------------------------------------------------------------------- |