瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助变种trojan.dl.agent.ndb和trojan.dl.mnless.mi怎么解决!!!

123   1  /  3  页   跳转

求助变种trojan.dl.agent.ndb和trojan.dl.mnless.mi怎么解决!!!

求助变种trojan.dl.agent.ndb和trojan.dl.mnless.mi怎么解决!!!

求助变种trojan.dl.agent.ndb和trojan.dl.mnless.mi怎么解决!!!
各位高手快来帮帮我啊
最后编辑2007-04-14 04:17:16
分享到:
gototop
 


下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
gototop
 

========Content========
2007-04-12,14:50:43

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Windows Publisher]
(KASStart)("C:\Program Files\Kingsoft\KSysCleaner\KASStart.EXE" -Startup) [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() [N/A]
(run)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(IMJPMIG8.1)("C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [(Verified)Microsoft Windows Publisher]
(runeip)(C:\Program Files\Rising\AntiSpyware\runiep.exe) [Beijing Rising Technology Co., Ltd.]
(RavTask)("C:\Program Files\Rising\Rav\RavTask.exe" -system) [Beijing Rising Technology Co., Ltd.]
(!AVG Anti-Spyware)("C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized) [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
(RavStub)("C:\PROGRAM FILES\RISING\RAV\ravstub.exe" /RUNONCE) [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [(Verified)Microsoft Windows Publisher]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
({57B86673-276A-48B2-BAE7-C6DBB3020EB8})(C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll) [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(cmdbcs)(; C:\WINDOWS\cmdbcs.exe) [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(; C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(mhsa)(; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso.exe) [N/A]
(mppdys)(; C:\WINDOWS\mppdys.exe) [N/A]
(mppsds)(; C:\WINDOWS\mppsds.exe) [N/A]
(msccrt)(; C:\WINDOWS\msccrt.exe) [N/A]
(PHIME2002A)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [(Verified)Microsoft Windows Publisher]
(PHIME2002ASync)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [(Verified)Microsoft Windows Publisher]
(SiS KHooker)(; C:\WINDOWS\system32\khooker.exe) [Silicon Integrated Systems Corporation]
(SiS Tray)(; C:\WINDOWS\system32\sistray.EXE) [Silicon Integrated Systems Corporation]
(StormCodec_Helper)(; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti) [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(svc)(; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\byetmr.exe) [N/A]
(swg)(; C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe) [(Verified)Google Inc]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(SynTPEnh)(; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe) [(Verified)Microsoft Windows Hardware Compatibility Publisher]
(SynTPLpr)(; C:\Program Files\Synaptics\SynTP\SynTPLpr.exe) [(Verified)Microsoft Windows Hardware Compatibility Publisher]
(wgs3)(; C:\WINDOWS\wgs3.exe) [N/A]
(wms3)(; C:\WINDOWS\wms3.exe) [N/A]
(wsttrs)(; C:\WINDOWS\wsttrs.exe) [N/A]


gototop
 

启动文件夹

N/A



--------------------------------------------------------------------------------



服务

[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
(C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe)(Anti-Malware Development a.s.)
[Indexing Data / BARCASE][Running/Auto Start]
(C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE C:\WINDOWS\SYSTEM32\WBEM\HQSCU.DLL,Export 1087)(Microsoft Corporation)
[Human Interface Device Access / HidServ][Stopped/Disabled]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A)
[Messenger / Messenger][Stopped/Disabled]
(C:\WINDOWS\system32\Down(0).EXE--)%SystemRoot%\System32\msgsvc.dll)(Microsoft Corporation)
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
("C:\Program Files\Rising\Rav\CCenter.exe")(Beijing Rising Technology Co., Ltd.)
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
("C:\PROGRAM FILES\RISING\RAV\Ravmond.exe")(Beijing Rising Technology Co., Ltd.)
[SmartLinkService / SLService][Running/Auto Start]
(slserv.exe)()
[Network Engine / Templates][Running/Auto Start]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)C:\WINDOWS\system32\gjrsz.dll)(Microsoft Corporation)
[Windows_Server / Windows_Server][Stopped/Auto Start]
(C:\WINDOWS\system32\rundell.exe)(N/A)



--------------------------------------------------------------------------------



驱动程序

[acpidisk / acpidisk][Running/Auto Start]
(\??\C:\WINDOWS\system32\drivers\acpidisk.sys)(N/A)
[ADProt / ADProt][Stopped/System Start]
(\SystemRoot\system32\drivers\ADProt.sys)(腾讯科技(深圳)有限公司)
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
(system32\drivers\ALCXSENS.SYS)(Sensaura)
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
(system32\drivers\ALCXWDM.SYS)(Realtek Semiconductor Corp.)
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
(\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys)(N/A)
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
(System32\DRIVERS\AvgAsCln.sys)(GRISOFT, s.r.o.)
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
(System32\DRIVERS\BaseTDI.SYS)(Beijing Rising Technology Co., Ltd.)
[ExpScaner / ExpScaner][Running/Auto Start]
(\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys)()
[HookCont / HookCont][Running/Auto Start]
(\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys)(Rising)
[HookReg / HookReg][Running/Auto Start]
(\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys)()
[HookSys / HookSys][Running/Auto Start]
(\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys)(Rising)
[kmsinput / kmsinput][Stopped/Manual Start]
(\??\C:\WINDOWS\system32\drivers\kmsinput.sys)(N/A)
[MEMSCAN / MEMSCAN][Running/Auto Start]
(\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys)(瑞星软件有限公司)
[Mtlmnt5 / Mtlmnt5][Running/Manual Start]
(system32\DRIVERS\Mtlmnt5.sys)()
[Mtlstrm / Mtlstrm][Stopped/Manual Start]
(system32\DRIVERS\Mtlstrm.sys)()
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
(system32\drivers\npf.sys)(CACE Technologies)
[npkcrypt / npkcrypt][Stopped/Auto Start]
(\??\C:\Program Files\Tencent\QQ\npkcrypt.sys)(N/A)
[NtMtlFax / NtMtlFax][Stopped/Manual Start]
(system32\DRIVERS\NtMtlFax.sys)()
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
(\SystemRoot\system32\drivers\RsBoot.sys)(Beijing Rising)
[rsdt / rsdt][Running/Auto Start]
(\??\C:\WINDOWS\system32\drivers\rsdt.sys)()
[RsNTGDI / RsNTGDI][Running/Boot Start]
(\SystemRoot\system32\Drivers\RsNTGdi.sys)(Beijing Rising Technology Co., Ltd.)
[RSPPSYS / RSPPSYS][Running/Auto Start]
(\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys)(Rising)
[Secdrv / Secdrv][Stopped/Manual Start]
(system32\DRIVERS\secdrv.sys)(N/A)
[SiS315 / SiS315][Running/Manual Start]
(system32\DRIVERS\sisgrp.sys)(Silicon Integrated Systems Corporation)
[SIS AGP Bus Filter / sisagp][Running/Boot Start]
(\SystemRoot\system32\DRIVERS\sisagp.sys)(Silicon Integrated Systems Corporation)
[SiS PCI Fast Ethernet Adapter Driver / SISNIC][Running/Manual Start]
(system32\DRIVERS\sisnic.sys)(SiS Corporation)
[SmartLink AMR_PCI Driver / Slntamr][Running/Manual Start]
(system32\DRIVERS\slntamr.sys)()
[SlNtHal / SlNtHal][Stopped/Manual Start]
(system32\DRIVERS\Slnthal.sys)()
[SlWdmSup / SlWdmSup][Running/Manual Start]
(system32\DRIVERS\SlWdmSup.sys)(Vireo Software)
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
(system32\DRIVERS\SynTP.sys)(Synaptics, Inc.)
[ttzy / ttzys][Running/Boot Start]
(\SystemRoot\System32\DRIVERS\ttzys.sys)(N/A)
[vdplmyt / vdplmyt][Stopped/Disabled]
(system32\drivers\vdplmyt.sys)()
gototop
 


浏览器加载项

[电影搜索]
{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} (C:\WINDOWS\system32\nethelp.dll, Microsoft Corporation)
[网页搜索]
{A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} (C:\WINDOWS\system32\sporder.dll, Microsoft Corporation)
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} (, N/A)
[网页搜索]
{0E1230F8-EA50-42A9-983C-D22ABC2EED3B} (C:\WINDOWS\system32\sporder.dll, Microsoft Corporation)
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} (C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, Powerise Digital)
[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} (C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com)
[电影搜索]
{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} (C:\WINDOWS\system32\nethelp.dll, Microsoft Corporation)
[网页搜索]
{0E1230F8-EA50-42A9-983C-D22ABC2EED3B} (C:\WINDOWS\system32\sporder.dll, Microsoft Corporation)
[PeerDraw Class]
{10072CEC-8CC1-11D1-986E-00A0C955B42E} (C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll, Microsoft Corporation)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} (, N/A)
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} (%SystemRoot%\system32\mshtml.dll, N/A)
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} (C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation)
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} (, N/A)
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} (C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation)
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[Thunder Browser Helper]
{63B2D652-EAD9-4D6E-93ED-2CC51D22CF02} (C:\WINDOWS\system32\XunLeiBHO_001.dll, N/A)
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} (C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation)
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} (%SystemRoot%\system32\SHELL32.dll, N/A)
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} (, N/A)
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} (C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation)
[电影搜索]
{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} (C:\WINDOWS\system32\SpOrder.Dll, Microsoft Corporation)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\system32\shdocvw.dll, N/A)
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} (C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation)
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} (C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.)
[&Net Search]
(res://C:\WINDOWS\system32\sporder.dll/MENUSEARCH.HTM, N/A)
gototop
 

正在运行的进程

[PID: 260][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 340][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 364][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1016][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\WINDOWS\system32\vjpvf.dll] [N/A, ]
[C:\WINDOWS\system32\mprss.dll] [N/A, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\system32\nethelp.dll] [Microsoft Corporation, 1, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
[PID: 1948][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1956][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1980][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2004][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 192][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2312][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 2480][D:\sreng2\SREng333.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------



Winsock 提供者

N/A



--------------------------------------------------------------------------------



Autorun.inf

N/A



--------------------------------------------------------------------------------



HOSTS 文件

127.0.0.1 localhost



--------------------------------------------------------------------------------



API HOOK

N/A



--------------------------------------------------------------------------------



隐藏进程

N/A

gototop
 

我也中了這個!!!怎麽殺啊?????急!!!!!!
gototop
 

病毒名称                        处理结果    发现日期              扫描方式            路径                                                                                                                    文件                                                                                                                    病毒来源                                                   
Trojan.PSW.QQRobber.bjm        删除成功    2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    Vldbjp.exe                                                                                                              本机                                                       
Trojan.PSW.ZhengTu.yl          删除成功    2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    3.dll>>UPX                                                                                                              本机                                                       
未知病毒                        删除成功    2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    twunk32.exe                                                                                                            本机                                                       
Trojan.PSW.Agent.ini            删除成功    2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    6.exe                                                                                                                  本机                                                       
Trojan.Tiny.d                  删除成功    2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    MS5C15C4.CPL                                                                                                            本机                                                       
Trojan.Tiny.d                  重新启动计算机后删除文件2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    hC15C49B.log                                                                                                            本机                                                       
Trojan.Tiny.d                  删除成功    2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    H7907113.log                                                                                                            本机                                                       
Trojan.Tiny.d                  删除成功    2007-04-11 11:24      手动扫描            C:\WINDOWS\system32                                                                                                    MS179071.CPL                                                                                                            本机                                                       
Trojan.PSW.XYOnline.hm          删除成功    2007-04-11 11:29      手动扫描            C:\WINDOWS\Temp                                                                                                        mh.exe                                                                                                                  本机
gototop
 

进到安全模式下[安全模式进入方法:重启电脑时按住F8 选择进入安全模式],
运行SREng-在"启动项目->注册表->删以下启动项目:
(cmdbcs)(; C:\WINDOWS\cmdbcs.exe) [N/A]
(svc)(; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\byetmr.exe) [N/A]
(mhsa)(; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso.exe) [N/A]
(mppdys)(; C:\WINDOWS\mppdys.exe) [N/A]
(mppsds)(; C:\WINDOWS\mppsds.exe) [N/A]
(msccrt)(; C:\WINDOWS\msccrt.exe) [N/A]
(wgs3)(; C:\WINDOWS\wgs3.exe) [N/A]
(wms3)(; C:\WINDOWS\wms3.exe) [N/A]
(wsttrs)(; C:\WINDOWS\wsttrs.exe) [N/A]

运行SREng-在"启动项目->服务->"Win32服务应用程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。  注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
[Windows_Server / Windows_Server][Stopped/Auto Start]
(C:\WINDOWS\system32\rundell.exe)(N/A)
[Indexing Data / BARCASE][Running/Auto Start]
(C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE C:\WINDOWS\SYSTEM32\WBEM\HQSCU.DLL,Export 1087)(Microsoft Corporation)

运行SREng-在"启动项目->服务->驱动程序"选中"隐藏已认证的微软服务" 然后将下面名称的驱动删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。  注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
删除:
[ttzy / ttzys][Running/Boot Start]
(\SystemRoot\System32\DRIVERS\ttzys.sys)(N/A)

删除以下文件:
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\mppdys.exe
C:\WINDOWS\wms3.exe
C:\WINDOWS\system32\winlib .dll
C:\WINDOWS\system32\mprss.dll
C:\WINDOWS\system32\vjpvf.dll
C:\WINDOWS\wsttrs.exe
C:\WINDOWS\System32\DRIVERS\ttzys.sys
C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE
C:\WINDOWS\SYSTEM32\WBEM\HQSCU.DLL
C:\WINDOWS\system32\rundell.exe

清空下临时文件夹 :C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
gototop
 

火影处理的真叫快。

学学
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT