瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 高手帮忙看下,机子是不是中马了..

1   1  /  1  页   跳转

高手帮忙看下,机子是不是中马了..

高手帮忙看下,机子是不是中马了..

未知家族病毒分析
扫描结果:
C:\WINDOWS\system32\NTdhcp.exe --> 与 Trojan.PSW.QQRobber 100%相似.


系统活动进程
C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\UPDTRAY.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\STARCENTER.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\JMESOFT\HOTKEY.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRA~1\JMESOFT\HKLOAD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\NTDHCP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\ALERT.EXE
D:\新建文件夹 (2)\RSDETECT.EXE

普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
SoundMan = SOUNDMAN.EXE
jmekey = C:\PROGRAM FILES\JMESOFT\HOTKEY.EXE
SiSPower = RUNDLL32.EXE SISPOWER.DLL,MODEAGENT
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
StormCodec_Helper = "C:\PROGRAM FILES\RINGZ STUDIO\STORM CODEC\STORMSET.EXE" /S /OPTI
Alert = C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\ALERT.EXE
StarCenter = C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\STARCENTER.EXE
AutoUpd = C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\UPDTRAY.EXE
stup.exe = C:\PROGRA~1\TENCENT\ADPLUS\STUP.EXE
AddrPlus3 = C:\PROGRA~1\TENCENT\ADPLUS\STUP.EXE C:\PROGRA~1\TENCENT\ADPLUS\ADPLUS.DLL RUNDLL32
NTdhcp = C:\WINDOWS\SYSTEM32\NTDHCP.EXE

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE

最后编辑2006-04-15 20:36:21
分享到:
gototop
 

QQ大盗。瑞星的监控应该已经开不了了。
结束进程C:\WINDOWS\SYSTEM32\NTDHCP.EXE
在注册表HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run下删除NTdhcp = C:\WINDOWS\SYSTEM32\NTDHCP.EXE项目
删除C:\WINDOWS\SYSTEM32\NTDHCP.EXE
之后瑞星的恢复参考http://forum.ikaka.com/topic.asp?board=28&artid=7866296

gototop
 

就是开者也是个壳
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT