AntiVirus 板


LINE

1.问题描述: 我不知道这个毒是中多久了,因为今天才出现问题,才想说扫毒看看...。 今天回家後发现网路有连线,但网页、msn等等都无法开启,重开机後,在刚连上网路 时,pcman、msn和网页都可以开启,但过一下子(不到一分钟),开启新网页时就连不上 ,已经连线的bbs站台和msn却可以正常使用,但将他关闭or断线後就又连不上,如果把 网路连线中断,再重新连线时,又有10几20秒的时间可以连上,随即又开始无法开网页 ,重新整理400多次还连不上,我想应该不是数据机或是网路的问题,因为室友的电脑 和网路都很正常。 2.扫毒报告: 抱歉现在没有办法开网页,不知道怎麽上传那个东西,我是用Norton扫的,扫出来 的有三个中毒,原本还有其他的也有扫到,不过那几个我有找到档案,把他丢到垃圾桶 ,後再删除掉了,而这三个如下: レベル    タイトル        处理   低レベル Tracking Cookie    无偿のスキャナで除去不能 高レベル W32.Spybot.Worm    无偿のスキャナで除去不能 高レベル W32.SillyDC      无偿のスキャナで除去不能 レベル应该是危险性吧,タイトル应该是病毒名称,而後面不知啥意思,反正无法删除 (我也搞不懂为啥会出现日文的Norton),至於病毒的位置如下: リスク名 リスク种类 档案位置 Tracking Cookie Cookie 这个没有看到档案位置,只有一堆类似 e-mail的东西,都是[email protected]/ 如Cookie:[email protected]/ Cookie:[email protected]/ W32.Spybot.Worm ウ イ ル ス c:\windows\system32\drivers\sysmon.exe u i ru su 他有写个"处理"和"感染",位置都是这个, 我到该资料夹找不到该档案。 c:\windows\system32\drivers\lbtwiz.exe 而这个只有写感染,也找不到档案。 W32.SillyDC ウイルス 同上面W32.Spybot.Worm的第一个, c:\windows\system32\drivers\sysmon.exe 也是找不到档案 找到的资料大概就这样了,不知道各位大大有没有点头绪可以帮助在下> <"!! 3.系统辅助分析软体扫描报告: 如无法使用网路请看 1 - 8 使用方式 这个等等研究完1-8後补上 4.报告连结: 请将扫描报告(log)贴於下方 (上面的全要) Combofix : Hijackthis: SRENG : 扫毒报告 : 唔...我扫完看到的东西都写在第二点上了@@" 缺得就是那三项各点进去时看到的东西,我加上来好了。 第一个 cookie: Cookie:[email protected]/ Cookie:[email protected]/cgi-bin Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/cgi-bin Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/sibulog/ Cookie:[email protected]/ Cookie:[email protected]/hc/9285139 Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ Cookie:[email protected]/ 第二个 処理: c:\windows\system32\drivers\sysmon.exe 感染: c:\windows\system32\drivers\sysmon.exe レジストリ: HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunServices\ ->Firewall Controls HKEY_USERS\S-1-5-21-343818398-1647877149-1801674531-1003\Software\Microsoft\ Windows\CurrentVersion\RunServices\->Firewall Controls HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunServices\-> Firewall Controls HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices\-> Firewall Controls HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\->Firewall Controls HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->SFCScan HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->246545 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->665578 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->7686743 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->rrrun HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\-> Microsoft Visual Application HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\AuthorizedApplications\List\->C:\WINDOWS\ system32\dllcache\winsno.exe HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunServices\-> ATI Video Driver Controls HKEY_USERS\S-1-5-21-343818398-1647877149-1801674531-1003\Software\Microsoft\ Windows\CurrentVersion\RunServices\->ATI Video Driver Controls HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunServices\-> ATI Video Driver Controls HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices\-> ATI Video Driver Controls HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunServices\-> Microsoft Directxsp HKEY_USERS\S-1-5-21-343818398-1647877149-1801674531-1003\Software\Microsoft\ Windows\CurrentVersion\RunServices\->Microsoft Directxsp HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunServices\-> Microsoft Directxsp HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices\-> Microsoft Directxsp HKEY_CLASSES_ROOT\CLSID\{1C047C97-CA7F-BAF1-05A4-AEBA271281ED} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\->ATI Video Driver Controls HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\->Microsoft Directxsp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->ATI Video Driver Controls HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\->Microsoft Directxsp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->1123 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\->112 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusOverride:0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->FirewallOverride:0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->Shell:Explorer.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\->Start:4 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry->Start:2 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr->Start:3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole->EnableDCOM:Y HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update->AUOptions:3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UpdatesDisableNotify:0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control-> WaitToKillServiceTimeout:20000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon->SFCDisable:0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa->restrictanonymous:0 感染: c:\windows\system32\drivers\lbtwiz.exe 第三个 処理: c:\windows\system32\drivers\systmon.exe 感染: c:\windows\system32\drivers\systmon.exe ファイル: c:\documents and settings\lu\local settings\temp\~df129c.tmp c:\documents and settings\lu\local settings\temp\~df16c6.tmp c:\documents and settings\lu\local settings\temp\~df1eaf.tmp c:\documents and settings\lu\local settings\temp\~df2f94.tmp c:\documents and settings\lu\local settings\temp\~df3147.tmp c:\documents and settings\lu\local settings\temp\~df31a7.tmp c:\documents and settings\lu\local settings\temp\~df4ff0.tmp c:\documents and settings\lu\local settings\temp\~df513e.tmp c:\documents and settings\lu\local settings\temp\~df527f.tmp c:\documents and settings\lu\local settings\temp\~df5914.tmp c:\documents and settings\lu\local settings\temp\~df5e6a.tmp c:\documents and settings\lu\local settings\temp\~df6a1b.tmp c:\documents and settings\lu\local settings\temp\~df8816.tmp c:\documents and settings\lu\local settings\temp\~df8b8e.tmp c:\documents and settings\lu\local settings\temp\~df9961.tmp c:\documents and settings\lu\local settings\temp\~dfadf3.tmp c:\documents and settings\lu\local settings\temp\~dfbdb9.tmp c:\documents and settings\lu\local settings\temp\~dfd6a.tmp c:\documents and settings\lu\local settings\temp\~dfe600.tmp c:\documents and settings\lu\local settings\temp\~dfe7a5.tmp c:\documents and settings\lu\local settings\temp\~dfede4.tmp レジストリ: HKEY_USERS\S-1-5-21-343818398-1647877149-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableRegistryTools:0 HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableRegistryTools:0 HKEY_USERS\S-1-5-21-343818398-1647877149-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1 HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer->NoDriveTypeAutoRun:0 HKEY_USERS\S-1-5-21-343818398-1647877149-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer->NoDriveTypeAutoRun:0 HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer->NoDriveTypeAutoRun:0 HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer->NoDriveTypeAutoRun:0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon->Shell:Explorer.exe HKEY_USERS\S-1-5-21-343818398-1647877149-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon->Shell HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run->SYSTMON.EXE 感染: c:\documents and settings\lu\local settings\temporary internet files\content.ie5\ufsf0bhx\tw[1].exe 好多...希望大家看得懂 > < 第三个最後写的那个感染,tw[1].exe我有找到,然後刚刚丢到垃圾桶删除了。 --



※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 61.227.193.146
1F:→ Limgog:1-8我看到是空的耶 @@ 12/15 03:10







like.gif 您可能会有兴趣的文章
icon.png[问题/行为] 猫晚上进房间会不会有憋尿问题
icon.pngRe: [闲聊] 选了错误的女孩成为魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一张
icon.png[心得] EMS高领长版毛衣.墨小楼MC1002
icon.png[分享] 丹龙隔热纸GE55+33+22
icon.png[问题] 清洗洗衣机
icon.png[寻物] 窗台下的空间
icon.png[闲聊] 双极の女神1 木魔爵
icon.png[售车] 新竹 1997 march 1297cc 白色 四门
icon.png[讨论] 能从照片感受到摄影者心情吗
icon.png[狂贺] 贺贺贺贺 贺!岛村卯月!总选举NO.1
icon.png[难过] 羡慕白皮肤的女生
icon.png阅读文章
icon.png[黑特]
icon.png[问题] SBK S1安装於安全帽位置
icon.png[分享] 旧woo100绝版开箱!!
icon.pngRe: [无言] 关於小包卫生纸
icon.png[开箱] E5-2683V3 RX480Strix 快睿C1 简单测试
icon.png[心得] 苍の海贼龙 地狱 执行者16PT
icon.png[售车] 1999年Virage iO 1.8EXi
icon.png[心得] 挑战33 LV10 狮子座pt solo
icon.png[闲聊] 手把手教你不被桶之新手主购教学
icon.png[分享] Civic Type R 量产版官方照无预警流出
icon.png[售车] Golf 4 2.0 银色 自排
icon.png[出售] Graco提篮汽座(有底座)2000元诚可议
icon.png[问题] 请问补牙材质掉了还能再补吗?(台中半年内
icon.png[问题] 44th 单曲 生写竟然都给重复的啊啊!
icon.png[心得] 华南红卡/icash 核卡
icon.png[问题] 拔牙矫正这样正常吗
icon.png[赠送] 老莫高业 初业 102年版
icon.png[情报] 三大行动支付 本季掀战火
icon.png[宝宝] 博客来Amos水蜡笔5/1特价五折
icon.pngRe: [心得] 新鲜人一些面试分享
icon.png[心得] 苍の海贼龙 地狱 麒麟25PT
icon.pngRe: [闲聊] (君の名は。雷慎入) 君名二创漫画翻译
icon.pngRe: [闲聊] OGN中场影片:失踪人口局 (英文字幕)
icon.png[问题] 台湾大哥大4G讯号差
icon.png[出售] [全国]全新千寻侘草LED灯, 水草

请输入看板名称,例如:Soft_Job站内搜寻

TOP