瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 大家帮我看一下这个木马要怎么杀掉!谢谢!

123   2  /  3  页   跳转

大家帮我看一下这个木马要怎么杀掉!谢谢!

[CODE]

2007-01-30,09:32:55

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><; C:\WINDOWS\system32\CTFMON.EXE>  [(Verified)Microsoft Corporation]
    <singress><; C:\Program Files\Sinfor\Ingress\ingress.exe -a>  [深圳市深信服电子科技有限公司]
    <KvXP><; "C:\Program Files\KV2006\KvXP.kxp" /ScanBoot /ScanSys>  [Jiangmin Co.Ltd]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <IgfxTray><C:\WINDOWS\system32\igfxtray.exe>  [(Verified)Intel Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <KvMonXP><; "C:\Program Files\KV2006\KVMonXP.kxp" /auto>  [Jiangmin Co.Ltd]
    <SKYNET Personal FireWall><C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe>  [广州众达天网技术有限公司]
    <Device Detector><; "C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" -autorun>  [N/A]
    <HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe>  [(Verified)Intel Corporation]
    <P8Waiting><; C:\Program Files\P8\P8Waiting.exe>  [http://www.P8.com/]
    <SoundMan><; SOUNDMAN.EXE>  [Avance Logic, Inc.]
    <StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
    <System><; C:\Program Files\Common Files\System\Updaterun.exe>  [N/A]
    <WebThunder><; C:\Program Files\Thunder Network\WebThunder\WebThunder.exe>  [N/A]
    <木马专家><; C:\Program Files\Trojan Expert 2007\mmzj.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ImpsSensor]
    <WinlogonNotify: ImpsSensor><ImpsSensor.dll>  [China Mobile]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\夜光时~1.SCR>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[KVSrvXP / KVSrvXP][Running/Auto Start]
  <C:\Program Files\KV2006\KVSrvXP.exe /Service><Jiangmin Co. Ltd>
[KVWSC / KVWSC][Running/Auto Start]
  <"C:\Program Files\KV2006\kvwsc.exe"><Jiangmin Co.Ltd>

==================================
驱动程序
[Service for Avance AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Avance Logic, Inc.>
[ialm / ialm][Running/Manual Start]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[KRegEx / KRegEx][Running/System Start]
  <\??\C:\PROGRA~1\KV2006\KRegEx.sys><Jiangmin Co. Ltd.>
[KSysCall Service / KSysCall][Running/System Start]
  <\??\C:\PROGRA~1\KV2006\KSysCall.sys><Jiangmin Co. Ltd.>
[KVDP_1 / KVDP_1][Running/Manual Start]
  <\??\C:\Program Files\KV2006\KVDP_1.sys><Jiangmin Co., Ltd.>
[KvMemon / KvMemon][Running/Manual Start]
  <\??\C:\PROGRA~1\KV2006\KvMemon.sys><Jiangmin Co. Ltd.>
[KVREDIR / KVREDIR][Running/System Start]
  <\??\C:\Program Files\KV2006\KVREDIR.sys><Jiangmin Co. Ltd>
[ncio / ncio][Running/Auto Start]
  <system32\DRIVERS\ncio.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Padus ASPI Shell / pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[PProtect / PProtect][Running/System Start]
  <\??\C:\PROGRA~1\KV2006\PProtect.sys><Jiangmin Co. Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SKNFW / SKNFW][Running/System Start]
  <\??\C:\WINDOWS\system32\Drivers\SKNFW.sys><N/A>
[SkyProcs / SkyProcs][Running/Manual Start]
  <\??\C:\PROGRA~1\SKYNET\FIREWALL\SkyProcs.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
  <system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
  <system32\drivers\ialmkchw.sys><Intel Corporation>

==================================
浏览器加载项
[Flashget Catch Url Class]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\PROGRA~1\FLASHGET\jccatch.dll, www.flashget.com>
[FiltrateWebObj Class]
  {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} <C:\Program Files\KV2006\KVBHO.dll, Jiangmin Co.Ltd>
[BHOObject Class]
  {C2476E25-E64F-47DE-B306-68322E057286} <C:\Program Files\NetMeeting\mscom.dll, TODO: <公司名>>
[gFlash Class]
  {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, >
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[快车]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, FlashGet.com>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <C:\Program Files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[快车(FlashGet)]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
[实用搜索工具条2.0]
  {03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, N/A>
[AtxIngress Class]
  {57A7BBE0-5A9D-46AA-A2C5-B994F186D9D8} <C:\Program Files\Sinfor\Ingress\acingress.dll, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[实用搜索工具条2.0]
  {03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Flashget Catch Url Class]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\PROGRA~1\FLASHGET\jccatch.dll, www.flashget.com>
[FiltrateWebObj Class]
  {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} <C:\Program Files\KV2006\KVBHO.dll, Jiangmin Co.Ltd>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <C:\Program Files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[BHOObject Class]
  {C2476E25-E64F-47DE-B306-68322E057286} <C:\Program Files\NetMeeting\mscom.dll, TODO: <公司名>>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[快车(FlashGet)]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
[gFlash Class]
  {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, >
[&使用快车(FlashGet)下载]
  <C:\PROGRA~1\FLASHGET\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
  <C:\PROGRA~1\FLASHGET\jc_all.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

gototop
 

正在运行的进程
[PID: 448][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 536][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 592][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 744][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 788][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 860][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 964][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1004][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1160][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1272][C:\WINDOWS\system32\netdde.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1468][C:\WINDOWS\system32\inetsrv\inetinfo.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1496][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\KV2006\KvShell.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 830]
    [C:\Program Files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [C:\Program Files\KV2006\lang\Kvxp0804.lng]  [N/A, N/A]
    [C:\Program Files\KV2006\APIImpl.dll]  [JiangMin Ltd., 9.0.0.500]
    [C:\WINDOWS\system32\igfxpph.dll]  [Intel Corporation, 3,0,0,2082]
    [C:\WINDOWS\system32\hccutils.DLL]  [Intel Corporation, 3,0,0,2082]
    [C:\WINDOWS\system32\igfxres.dll]  [Intel Corporation, 3,0,0,2082]
    [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,2082]
    [C:\WINDOWS\system32\igfxdev.dll]  [Intel Corporation, 3,0,0,2082]
    [C:\WINDOWS\Vista\Rtback\ContextBG.dll]  [Grigri, 1, 0, 0, 1]
    [C:\Program Files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
    [C:\Program Files\KV2006\KVBHO.dll]  [Jiangmin Co.Ltd, 9.0.6.0113]
    [C:\Program Files\KV2006\KVAddrDb.dll]  [Jiangmin Co.Ltd, 9, 0, 0, 1018]
    [C:\PROGRA~1\FLASHGET\fgmgr.dll]  [www.flashget.com, 1, 8, 0, 1001]
[PID: 1528][C:\Program Files\KV2006\KVSrvXP.exe]  [Jiangmin Co. Ltd, 9.2.0.50822]
    [C:\Program Files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [C:\Program Files\KV2006\SvcSafe.dll]  [Jiangmin Co. Ltd, 9, 2, 0, 51107]
    [C:\Program Files\KV2006\lang\SvcSafe0804.lng]  [N/A, N/A]
    [C:\Program Files\KV2006\RegProt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 1212]
    [C:\Program Files\KV2006\Scan.dll]  [Jiangmin Co., Ltd., 1.0.6.07110]
    [C:\Program Files\KV2006\FileGD.dll]  [Jiangmin Co.Ltd, 9.2.0.50809]
    [C:\Program Files\KV2006\KvSPI.dll]  [Jiangmin Co. Ltd., 1.0.6.1024]
    [C:\Program Files\KV2006\lang\KVSpi0804.lng]  [N/A, N/A]
    [C:\Program Files\KV2006\ScanHost.dll]  [Jiangmin Co. Ltd, 9, 2, 0, 50822]
    [C:\Program Files\KV2006\KVWPSet.dll]  [Jiangmin Co.Ltd, 9, 0, 0, 60220]
    [C:\Program Files\KV2006\EngPS.dll]  [Jiangmin Co.Ltd, 9, 2, 0, 50817]
    [C:\Program Files\KV2006\KVEnhS.dll]  [Jiangmin Co., Ltd., 9, 2, 6, 02040]
    [C:\Program Files\KV2006\KVEnhJ.dll]  [Jiangmin Co.Ltd, 9, 1, 0, 50822]
    [C:\Program Files\KV2006\KVExtCab.dll]  [JiangMin Co. Ltd, 9, 2, 0, 50822]
    [C:\Program Files\KV2006\KVExtLZH.dll]  [JiangMin Co. Ltd., 9, 2, 6, 0316]
    [C:\Program Files\KV2006\KvExtZip.dll]  [JiangMin Co Ltd., 9, 2, 0, 50822]
    [C:\Program Files\KV2006\KVExtZ.dll]  [Jiangmin Co. Ltd, 9.2.0.503]
    [C:\Program Files\KV2006\KVExtTar.dll]  [Jiangmin Co. Ltd, 9, 2, 0, 50822]
    [C:\Program Files\KV2006\KVExtEml.dll]  [Jiangmin Co. Ltd., 9, 2, 6, 07050]
    [C:\Program Files\KV2006\lang\KVExtEml0804.lng]  [N/A, N/A]
    [C:\Program Files\KV2006\KvExtRar.dll]  [JiangMin Co. Ltd., 9, 2, 6, 04020]
    [C:\Program Files\KV2006\KVExtGz.dll]  [Jiangmin Co. Ltd, 9, 0, 6, 04200]
    [C:\Program Files\KV2006\KVEnhK.dll]  [Jiangmin Co.Ltd, 9, 1, 0, 51209]
    [C:\Program Files\KV2006\Fix.dll]  [Jiangmin Co.Ltd, 9, 2, 6, 07110]
    [C:\Program Files\KV2006\KvCkMail.dll]  [N/A, 9, 0, 6, 619]
    [C:\Program Files\KV2006\lang\KvMailRes0804.lng]  [N/A, N/A]
    [C:\Program Files\KV2006\lang\PrivateCfg0804.lng]  [TODO: <Company name>, 1.0.0.1]
[PID: 1572][C:\Program Files\KV2006\kvwsc.exe]  [Jiangmin Co.Ltd, 9, 0, 5, 908]
    [C:\Program Files\KV2006\EngPS.dll]  [Jiangmin Co.Ltd, 9, 2, 0, 50817]
    [C:\Program Files\KV2006\EngFace.dll]  [Jiangmin Co.Ltd, 9.0.0.50809]
    [C:\Program Files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
[PID: 1604][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 1676][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
    [C:\Program Files\KV2006\KVMonXP.kxp]  [Jiangmin Co.Ltd, 9, 2, 0, 60905]
    [C:\Program Files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [C:\Program Files\KV2006\lang\Kvxp0804.lng]  [N/A, N/A]
    [C:\Program Files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
    [C:\Program Files\KV2006\EngFace.dll]  [Jiangmin Co.Ltd, 9.0.0.50809]
    [C:\Program Files\KV2006\EngPS.dll]  [Jiangmin Co.Ltd, 9, 2, 0, 50817]
    [C:\Program Files\KV2006\KvMemory.dll]  [Jiangmin Co. Ltd., 9, 0, 6, 0214]
    [C:\Program Files\KV2006\KvOffice.dll]  [JiangMin New Tech., 9.0.0.1213]
    [C:\Program Files\KV2006\lang\KVOffice0804.lng]  [N/A, N/A]
    [C:\Program Files\KV2006\VirusUpload.dll]  [N/A, 2, 16, 6, 7260]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\Program Files\KV2006\PProtect.dll]  [Jiangmin Co. Ltd., 9.0.0.921]
    [C:\Program Files\KV2006\lang\PrivateCfg0804.lng]  [TODO: <Company name>, 1.0.0.1]
gototop
 

[C:\Program Files\KV2006\ComUIPS.dll]  [Jiangmin Ltd., 9. 5. 5. 20]
[PID: 228][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 240][C:\Program Files\Sinfor\Ingress\ingress.exe]  [深圳市深信服电子科技有限公司, 1, 0, 0, 1]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\Program Files\KV2006\TrojDie.kxp]  [Jiangmin Co.Ltd, 9.0.6.0413]
    [C:\Program Files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [C:\Program Files\KV2006\lang\TrojDie0804.lng]  [Jiangmin Co.Ltd, 9.0.0.0813]
    [C:\Program Files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
    [C:\Program Files\KV2006\PProtect.dll]  [Jiangmin Co. Ltd., 9.0.0.921]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\Program Files\KV2006\ComUIPS.dll]  [Jiangmin Ltd., 9. 5. 5. 20]
[PID: 2100][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2140][C:\Program Files\KV2006\KRegEx.exe]  [Jiangmin Co.Ltd, 9.0.6.210]
    [C:\Program Files\KV2006\KRegEx.dll]  [Jiangmin Co. Ltd., 9.0.6.0119]
    [C:\Program Files\KV2006\KRegTrust.dll]  [Jiangmin Co. Ltd., 9.0.0.825]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 2412][C:\Program Files\KV2006\UIHost.exe]  [Jiangmin Co. Ltd, 9.2.0.50822]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\Program Files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [C:\Program Files\KV2006\ComUI.dll]  [Jiangmin Ltd., 9. 0. 0.509]
    [C:\Program Files\KV2006\ComUIPS.dll]  [Jiangmin Ltd., 9. 5. 5. 20]
    [C:\Program Files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
[PID: 3196][D:\安全\新建文件夹\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 2484][C:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\Program Files\Tencent\QQ\RICHED20.dll]  [N/A, 9, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\GroupLive.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, N/A]
    [C:\Program Files\KV2006\KVGuard.dll]  [Jiangmin Co Ltd, 9.0.0.813]
    [C:\Program Files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [C:\Program Files\KV2006\lang\KVGuard0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
    [C:\Program Files\KV2006\KVAddrDb.dll]  [Jiangmin Co.Ltd, 9, 0, 0, 1018]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Program Files\Tencent\QQ\VPortal.dll]  [, 1, 0, 0, 4]
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, N/A]
[PID: 992][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\Program Files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1 mmsk.cn
127.0.0.1 bbs.mmsk.cn
127.0.0.1 www.mmsk.cn
127.0.0.1 soudong.com
127.0.0.1 www.soudong.com

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
入口点错误:CreateRemoteThread

==================================


[/CODE]
gototop
 

好了,都发上去了,不好意思啊,刚才没发好,电脑突然断了会线~~
gototop
 

你试试下载江民2007下载版杀一下,然后再重装kv2006,在对付这种病毒(熊猫除外)我通常都是这么干的呵呵,记得要在机器上安装防火墙,虽然影响速度,但是,鉴于你电脑的重要性,还是安全第一吧!
gototop
 

我一直都有装防火墙的,是天网的。而且我也都有打系统补丁,该关掉的端口也都关掉了,我想应该是浏览了挂了马的网站中的吧。我现在就是用江民的,都升级到最新版本的。我就是在注册表里找不到想关的启动项。
gototop
 

还存在的一个问题就是:我没办法关掉IPC共享,我试了几种方法都不行啊,用超级兔子、进入cmd里用net share命令,用江民的木马一扫光都不行。。是不是问题就是出在这个上啊
gototop
 

我查了一下,它说是 木马根据我系统存在的漏洞和弱口令让我中招的,可是我也有打系统补丁,而且我也改了administrator这个管理员的名字,并且设了一个比较复杂的系统密码。我想不大明白。请帮忙分析一下中招的原因好吗?
gototop
 

我现在又用江民的系统漏洞和弱口令检查扫描了一下,扫出了报告却看不到什么东西,是这样一张图片。

附件附件:

下载次数:308
文件类型:image/pjpeg
文件大小:
上传时间:2007-1-30 11:00:51
描述:



gototop
 

运行sreng2启动项目,注册表删除
<System><; C:\Program Files\Common Files\System\Updaterun.exe> [N/A]
重启后删除C:\Program Files\Common Files\System\Updaterun.exe

testrun.exe没看到,你已经删了?
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT