卡巴老是提示我发现危险,让我处理,但我处理时,却发现病毒已经全部删除了,但卡巴还是提示我发现危险,请处理,我都不知道该怎么办了.我再问一下扫描中有RVA错误,这是个什么错误,有什么影响吗?该怎么处理?下面是我的扫描日志文件,哪位大侠给看一下:
- 2007-05-16,10:28:45
- System Repair Engineer 2.4.12.806
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <ThunderMini><C:\Program Files\Thunder Network\ThunderMini\ThunderMiniShell.exe> []
- <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
- [HKEY_CURRENT_USER\Control Panel\Desktop]
- <SCRNSAVE.EXE><C:\WINDOWS\system32\BLISS.SCR> [Microsoft]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [Kaspersky Anti-Virus 6.0 / AVP][Running/Auto Start]
- <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [tjmysql / tjmysql][Running/Auto Start]
- <D:\hrims_statistic\mysql\bin\mysqld-nt --defaults-file=D:\hrims_statistic\mysql\my.ini tjmysql><N/A>
- [tjtomcat / tjtomcat][Running/Auto Start]
- <D:\hrims_statistic\tomcat5.0\bin\tomcat5.exe //RS//tjtomcat><Apache Software Foundation>
- ==================================
- 驱动程序
- N/A
- ==================================
- 浏览器加载项
- [ThunderMini Browser Helper]
- {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
- [启动迅雷5]
- {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <e:\xxy2006\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
- [网页]
- {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
- [Microgarden WebTools]
- {E929661E-3728-4E52-BCCB-AE4058F75466} <E:\xxy2006\Microgarden WebTools\WebTools.dll, Microgarden LLC>
- [DSO Framer Control Object]
- {00460182-9E5E-11D5-B7C8-B8269041DD57} <C:\WINDOWS\system32\RiseWord.ocx, 国家信息中心学术委员会软件评测研究中心>
- [RiseSelObj Control]
- {B53903D5-F777-4A9A-BFC7-63689541257E} <C:\WINDOWS\DOWNLO~1\RISESE~1.OCX, 软件测评研究院>
- [SAXFile FileDownload ActiveX Control]
- {B82FA17C-F3A9-11D2-B5DD-0050041B7FF6} <C:\WINDOWS\system32\Softartisans\SAXFile\saaxfile.dll, SoftArtisans, Inc. (http://www.softartisans.com)>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
- [ComponentOne FlexGrid 7.1 (OLEDB)]
- {D76D712E-4A96-11D3-BD95-D296DC2DD072} <C:\WINDOWS\Downloaded Program Files\vsflex7.ocx, ComponentOne>
- [RiseOfficeCtl Class]
- {FA80B292-5BF9-4617-975C-01C02BFA49B0} <C:\WINDOWS\system32\RISEOF~1.DLL, 国家信息中心软件评测>
- [ThunderMini Browser Helper]
- {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
- [RiseSelObj Control]
- {B53903D5-F777-4A9A-BFC7-63689541257E} <C:\WINDOWS\DOWNLO~1\RISESE~1.OCX, 软件测评研究院>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
- [Microgarden WebTools]
- {E929661E-3728-4E52-BCCB-AE4058F75466} <E:\xxy2006\Microgarden WebTools\WebTools.dll, Microgarden LLC>
- [RiseOfficeCtl Class]
- {FA80B292-5BF9-4617-975C-01C02BFA49B0} <C:\WINDOWS\system32\RISEOF~1.DLL, 国家信息中心软件评测>
- [&使用迷你迅雷下载]
- <C:\Program Files\Thunder Network\ThunderMini\Program\GetUrl.htm, N/A>
- [上传到QQ网络硬盘]
- <E:\myfile\qq\AddToNetDisk.htm, N/A>
- [使用迅雷下载]
- <e:\xxy2006\Thunder\Program\GetUrl.htm, N/A>
- [使用迅雷下载全部链接]
- <e:\xxy2006\Thunder\Program\GetAllUrl.htm, N/A>
- [导出到 Microsoft Office Excel(&X)]
- <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
- ==================================
- 正在运行的进程
- [PID: 636][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 716][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 740][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 784][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 796][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 948][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1012][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1128][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.374 (winmain(wmbla).070416-2057)]
- [PID: 1532][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 1.0.6.411]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll] [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
- [PID: 1728][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1824][C:\Program Files\Thunder Network\ThunderMini\program\ThunderMini.exe] [Thunder Networking Technologies,LTD, 2, 0, 0, 29]
- [C:\Program Files\Thunder Network\ThunderMini\program\download_interface.dll] [N/A, ]
- [C:\Program Files\Thunder Network\ThunderMini\program\UpdateDownload.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 6]
- [C:\Program Files\Thunder Network\ThunderMini\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 6]
- [e:\xxy2006\Thunder\Components\InMedia\iEmbed09.dll] [ , 3, 3, 0, 80]
- [PID: 528][C:\WINDOWS\system32\BRMFRSMG.EXE] [Brother Industries, Ltd., 1.45.15.340]
- [C:\WINDOWS\system32\BREVIF.dll] [Brother Industries, Ltd., 1.45.15.340]
- [C:\WINDOWS\system32\BrSerIf.DLL] [Brother Industries, Ltd., 1.45.15.340]
- [C:\WINDOWS\system32\BrmfLPT.DLL] [Brother Industries, Ltd., 1.45.15.346]
- [C:\WINDOWS\system32\BrBiDiIf.DLL] [Brother Industries, Ltd., 1.45.15.340]
- [PID: 3632][E:\xxy2006\同花顺核新\hexin.exe] [上海核新软件技术有限公司, 2007, 2, 5, 84]
- [E:\xxy2006\同花顺核新\RICHED20.dll] [Microsoft Corporation, 5.30.23.1205]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 1.0.6.411]
- [PID: 2128][E:\xxy2006\同花顺核新\GLT.exe] [上海核新软件技术有限公司, 2006, 10, 9, 1]
- [E:\xxy2006\同花顺核新\sqlite30.dll] [上海核新软件技术有限公司, 2005, 5, 12, 0]
- [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 1.0.6.411]
- [E:\xxy2006\同花顺核新\RICHEDTW.DLL] [Microsoft Corporation, 5.00.2134.1]
- [E:\xxy2006\同花顺核新\RICHED20.dll] [Microsoft Corporation, 5.30.23.1205]
- [PID: 524][E:\xxy2006\同花顺核新\LiveUpdate.exe] [上海核新软件技术有限公司, 2006, 11, 2, 0]
- [E:\xxy2006\同花顺核新\RICHED20.dll] [Microsoft Corporation, 5.30.23.1205]
- [PID: 3448][E:\xxy2006\tddownload\sreng2-1\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- API HOOK
- RVA 错误: LoadLibraryA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF3D4BB25)
- RVA 错误: LoadLibraryExA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF3D4BD67)
- RVA 错误: LoadLibraryExW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF3D4BF0B)
- RVA 错误: LoadLibraryW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF3D4BC49)
- RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: Dest Addr: 0xF3D4BE8F)
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码 |