瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 高手请进:如何删除可恶的木马病毒?

123   1  /  3  页   跳转

高手请进:如何删除可恶的木马病毒?

高手请进:如何删除可恶的木马病毒?

我用的是XP专业版和FAT32文件格式,安装卡巴斯基杀毒软件木马克星。在我的电脑里c:\windows\system32\NTService32.dll,木马克星说是木马,提示重启后删除,重启后依然存在。卡巴斯基说是一个广告程序,也是提示重启删除,但重启后也是还存在。我又到安全模式下用木马克星和卡巴斯基查了一遍,还是清除不掉。后来用Killbox,正常情况下提示无法清除,也只能在重启后删除,但重启依然存在。最后我自己手工删除,启动到纯DOS,删除时却提示:File not found。考虑到该文件可能隐藏了,于是使用Attrib命令取消该文件的隐藏属性,却提示This program cannot be run in dos mode。意思是说attrib命令不能运行在dos模式。我很奇怪,于是用这个命令取消其它文件的隐藏属性,发现这个命令是可以使用的。不知道这个病毒使用了什么反删除高招,在DOS下居然不能被发现和删除。后来我把这个病毒发到http://www.virustotal.com/en/indexf.html,返回如下信息:
[ scan result ]
AhnLab-V3    2007.3.19.0/20070319    found nothing
AntiVir    7.3.1.43/20070319    found [ADSPY/Agent.BC]
Authentium    4.93.8/20070317    found nothing
Avast    4.7.936.0/20070319    found [Win32:Adware-gen.]
AVG    7.5.0.447/20070318    found [Adware Generic.SWQ]
BitDefender    7.2/20070319    found nothing
CAT-QuickHeal    9.00/20070315    found [AdWare.Agent.bc (Not a Virus)]
ClamAV    0.90.1/20070319    found nothing
DrWeb    4.33/20070319    found nothing
eSafe    7.0.14.0/20070316    found [Win32.Dropper]
eTrust-Vet    30.6.3491/20070319    found nothing
Ewido    4.0/20070318    found [Adware.Zhongsou]
F-Prot    4.3.1.45/20070317    found nothing
F-Secure    6.70.13030.0/20070319    found nothing
FileAdvisor    1/20070319    found nothing
Fortinet    2.85.0.0/20070319    found [Adware/Agent]
Ikarus    T3.1.1.3/20070319    found nothing
Kaspersky    4.0.2.24/20070319    found [not-a-virus:AdWare.Win32.Agent.bc]
McAfee    4986/20070316    found [potentially unwanted program Adware-ZangoSA]
Microsoft    1.2306/20070319    found nothing
NOD32v2    2125/20070318    found [Win32/Adware.Zhongsou]
Norman    5.80.02/20070316    found nothing
Panda    9.0.0.4/20070318    found [Trj/Agent.DLK]
Prevx1    V2/20070319    found [Trojan.IEPoser]
Sophos    4.15.0/20070313    found nothing
Sunbelt    2.2.907.0/20070316    found [Trojan-Dropper.Multi.Gen]
Symantec    10/20070319    found [Trojan.Dropper]
TheHacker    6.1.6.076/20070315    found [Adware/Agent.bc]
UNA    1.83/20070316    found [Adware.Agent.6392]
VBA32    3.11.2/20070318    found [Application.Win32.Adware.Zhongsou]
VirusBuster    4.3.7:9/20070318    found nothing
从返回的结果来看:所有主流杀毒软件认为该文件NTService32.dll还是有问题的。诺顿认为它是木马,卡巴和麦咖啡认为它是一个广告程序。
我比较了该文件和其它dll文件的属性,发现还是有很大区别的:该目录下其它dll文件的属性都是存档属性,隐藏属性不是灰色的,可以勾选,如图所示。

附件附件:

下载次数:657
文件类型:image/pjpeg
文件大小:
上传时间:2007-3-25 12:13:18
描述:
预览信息:EXIF信息



最后编辑2007-04-03 13:14:11
分享到:
gototop
 

而该文件的隐藏属性居然是灰色,只读属性。不知是不是这个原因,造成该文件在dos下不能被修改属性和被删除。具体如图所示。

附件附件:

下载次数:630
文件类型:image/pjpeg
文件大小:
上传时间:2007-3-25 12:14:11
描述:
预览信息:EXIF信息



gototop
 

万般无奈之下,我又切换到安全模式,首先打开注册表,发现了run键下的可疑之处,如图所示:Desktop键值的数据居然调用了NTService32.dll,赶紧删除该键值,但刷新一下,该键值又自动恢复了。估计是跟NTService32.dll没有删除有关。

附件附件:

下载次数:640
文件类型:image/pjpeg
文件大小:
上传时间:2007-3-25 12:14:46
描述:
预览信息:EXIF信息



gototop
 

看这一招无用,于是又调用msconfig,发现启动项目中有NTService32,如图所示,于是把它禁止。

附件附件:

下载次数:643
文件类型:image/pjpeg
文件大小:
上传时间:2007-3-25 12:15:41
描述:
预览信息:EXIF信息



gototop
 

再切换到服务标签,停止Windows NT Service服务,如图所示。最后重启计算机,发现msconfig中我修改的内容又都恢复了原样!!

附件附件:

下载次数:690
文件类型:image/pjpeg
文件大小:
上传时间:2007-3-25 12:16:14
描述:
预览信息:EXIF信息



gototop
 

我现在已经彻底失望了,不知该如何删除这个可恶的木马病毒。下面是我用SREng扫描的结果,大家帮忙分析一下:
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><; C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
<kis><; "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"> [Kaspersky Lab]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Component Publisher]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Publisher]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><> [N/A]

==================================
启动文件夹
N/A

==================================
服务
[卡巴斯基互联网安全套装 6.0 / AVP][Running/Auto Start]
<"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[System Local Kernel Service / kernel][Stopped/Auto Start]
<"C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\zzRc0pXAzy.exe"><N/A>
[Logical Disk Manager Administrator Service / Logical Disk Manager Administrator Service][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ntxml.dll><>
[Windows NetWork Management / NvCore][Stopped/Auto Start]
<><N/A>
[Distributed Link Tracking Clientbjh / ServiceBJH][Stopped/Auto Start]
<><N/A>
[Windows NT Service32 / Windows NT Service32][Stopped/Auto Start]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
gototop
 

驱动程序
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[msprotect / msprotect][Running/System Start]
<system32\DRIVERS\msprotect.sys><Windows (R) 2000 DDK provider>
[Mtlmnt5 / Mtlmnt5][Stopped/Manual Start]
<system32\DRIVERS\Mtlmnt5.sys><>
[Mtlstrm / Mtlstrm][Stopped/Manual Start]
<system32\DRIVERS\Mtlstrm.sys><>
[ncio / ncio][Stopped/Auto Start]
<system32\DRIVERS\ncio.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
[NtMtlFax / NtMtlFax][Stopped/Manual Start]
<system32\DRIVERS\NtMtlFax.sys><>
[parcls / parcls][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\parcls.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RecAgent / RecAgent][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\RecAgent.sys><>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SmartLink AMR_PCI Driver / Slntamr][Stopped/Manual Start]
<system32\DRIVERS\slntamr.sys><>
[SlNtHal / SlNtHal][Stopped/Manual Start]
<system32\DRIVERS\Slnthal.sys><>
[SlWdmSup / SlWdmSup][Stopped/Manual Start]
<system32\DRIVERS\SlWdmSup.sys><>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
<system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[tchxzu9 / tchxzu97][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\tchxzu97.sys><N/A>
[TSP / TSP][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
<system32\drivers\vinyl97.sys><VIA Technologies, Inc.>
[wbmkwm6 / wbmkwm62][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\wbmkwm62.sys><N/A>
[ws2ifsd / ws2ifsd][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ws2ifsd.sys><N/A>
[yzaf / yzafx][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\yzafx.sys><N/A>
[zhlxgk0 / zhlxgk03][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\zhlxgk03.sys><N/A>

==================================
浏览器加载项
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, N/A>
[MyLoader Class]
{09BA1AA9-CAD4-4C14-BDE6-922DFF5F6F38} <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEMDATA\pPnipgqJby_2001.dll, >
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab>
[迅雷]
{1FBA04EE-3024-11D2-8F1F-000019796948} <C:\Program Files\Sandai Technologies Inc\Thunder\Thunder.exe, 深圳市三代科技开发有限公司>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <, N/A>
[Windows Live Safety Center Base Module]
{5ED80217-570B-4DA9-BF44-BE107C0EC166} <C:\WINDOWS\Downloaded Program Files\wlscBase.dll, Microsoft Corporation>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, N/A>
[MyLoader Class]
{09BA1AA9-CAD4-4C14-BDE6-922DFF5F6F38} <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEMDATA\pPnipgqJby_2001.dll, >
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <, N/A>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Windows Live Safety Center Base Module]
{5ED80217-570B-4DA9-BF44-BE107C0EC166} <C:\WINDOWS\Downloaded Program Files\wlscBase.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[WangWangObj Class]
{6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <C:\Program Files\Alisoft\Alitalk\WangWangX4.dll, 阿里软件(中国)有限公司>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Windows Live Safety Center Control Module]
{8E5C8BEE-1887-414C-8AC9-7C3951F28476} <C:\Program Files\Windows Live Safety Center\wlscCtrl.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[InfoCheck Class]
{F91BA567-79B9-467E-BC97-5DBA01BBC5EE} <C:\Program Files\Alisoft\Alitalk\Ali_Check.dll, >
[InstallCheck Class]
{FFB8C97E-39D4-4E8A-9FE4-B451A0D6CA65} <C:\Program Files\Alisoft\Alitalk\Ali_Check.dll, >
[&使用迅雷下载]
<C:\Program Files\Sandai Technologies Inc\Thunder\geturl.htm, N/A>
[Google 搜索(&G)]
<, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 596][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 652][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 676][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 720][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 732][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 892][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
[c:\windows\system32\ntxml.dll] [, 1, 0, 0, 1]
[PID: 1828][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\Downloaded Program Files\904185\ExDLL.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\webpageparser.dll] [N/A, ]
[C:\WINDOWS\system32\Charset.dll] [N/A, ]
[C:\WINDOWS\system32\CreateDomTree.dll] [N/A, ]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll] [Nero AG, 2, 0, 0, 8]
[C:\Program Files\Common Files\Ahead\Lib\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\shellex.dll] [Kaspersky Lab, 6.0.0.299]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.3929]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3929]
[PID: 1468][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1376][C:\Program Files\SREng\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]

==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1 localhost

==================================
API HOOK
RVA 错误: LoadLibraryA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF108AB25)
RVA 错误: LoadLibraryExA (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF108AD67)
RVA 错误: LoadLibraryExW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF108AF0B)
RVA 错误: LoadLibraryW (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0xF108AC49)
RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: Dest Addr: 0xF108AE8F)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

而且电脑还时不时出现一些不知名的木马,比如ctfmon.exe,watmfds32.dll,pvsec.dll,ofhqw.dll等,用木马克星杀掉后再查找时确实没有了,但过一段时间又有其它名称的木马出来了。但NTService32.dll就是删除不了。估计这些木马都是它释放的。
gototop
 

如果谁想要NTService32.dll这个木马病毒样本,可以给我回复。
gototop
 

首先下载软件http://download.pchome.net/utility/antivirus/trojan/20621.html
费尔木马强力助手
然后重启计算机进入
安全模式下(开机后不断 按F8键  然后出来一个高级菜单 选择第一项 安全模式 进入系统)
打开费尔木马强力助手  在文件名处输入如下文字
C:\WINDOWS\System32\DRIVERS\zhlxgk03.sys
C:\WINDOWS\System32\DRIVERS\yzafx.sys
C:\WINDOWS\system32\drivers\ws2ifsd.sys
C:\WINDOWS\System32\DRIVERS\wbmkwm62.sys
C:\WINDOWS\System32\DRIVERS\tchxzu97.sys
然后选中清除 并抑制文件再次生成  开始

打开sreng (就是你扫日志的软件)启动项目  注册表 删除如下项目 (如果有哪项你认识或者确认不是病毒 请不要删除)<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> [N/A]
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><> [N/A]

“启动项目”-“服务”-“Win32服务应用程序”中点“隐藏经认证的微软项目”,
选中以下项目,点“删除服务”,再点“设置”,在弹出的框中点“否”:

Logical Disk Manager Administrator Service / Logical Disk Manager Administrator Service
Windows NT Service32 / Windows NT Service32

在“启动项目”-“服务”-“驱动程序”中点“隐藏经认证的微软项目”,
选中以下项目,点“删除服务”,再点“设置”,在弹出的框中点“否”:
parcls / parcls
zhlxgk0 / zhlxgk03
yzaf / yzafx
ws2ifsd / ws2ifsd
wbmkwm6 / wbmkwm62
tchxzu9 / tchxzu97



双击我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉。
然后删除C:\WINDOWS\system32\NTService32.dll
C:\WINDOWS\system32\ntxml.dll
C:\WINDOWS\system32\drivers\parcls.sys
C:\WINDOWS\system32\PvSec.dll
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT