瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 查不到木马,但每次开机时提示?

1   1  /  1  页   跳转

查不到木马,但每次开机时提示?

查不到木马,但每次开机时提示?

我每次开机时,瑞星提示有木马,并成功删除,但是在下一次开机时又会有这样的提示,用瑞星杀也杀不着,查也查不到,用木马清除器也查不到,请高手帮忙解决。谢谢!这是木马名称:NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
最后编辑2005-07-21 20:31:03
分享到:
gototop
 

用hijackthis1.99.1版

把扫出的日志内容复制贴到贴子上来.
gototop
 

详细内容2005-07-19 04:48:49, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-19 04:48:51, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-20 09:13:46, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-20 09:13:50, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-20 18:13:03, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-20 18:13:04, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-20 21:52:44, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-20 21:52:45, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-21 06:37:06, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-21 06:37:30, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-21 06:39:33, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-21 06:39:38, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-21 11:40:05, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-21 11:40:06, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-21 19:02:58, hxadsec.exe>>C:\WINDOWS\system32\hxadsec.exe ->Trojan.Clicker.Adsec.d
详细内容2005-07-21 19:02:59, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
详细内容2005-07-21 19:11:04, NTdhcp.exe>>C:\WINDOWS\System32\NTdhcp.exe ->Trojan.PSW.QQRobber.15.d
以上是我这几天每次开机时提示的木马。请高手帮助解决,谢谢。
gototop
 

汗```

打开附件中的工具,扫描系统后点保存,把生成的日志内容复制贴到贴子上来.

附件:hijackthis1.99.1

附件附件:

下载次数:0
文件类型:application/octet-stream
文件大小:
上传时间:2005-7-21 19:30:45
描述:

gototop
 

建议DOS下杀
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 19:42:03, on 2005-7-21
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
e:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
e:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Sandai\ThunderMini\ThunderMini.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Sandai\ThunderMini\TDUpdate.exe
e:\program files\rising\rfw\RfwCfg.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
e:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.335\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-

1D9571695F55} - C:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: URLMonitor Class - {3ED9FFDA-79DB-4B2D-99B7-16EA3C4A3A92} -

C:\WINDOWS\System32\hap.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} -

E:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14}

- C:\WINDOWS\System32\winhtp.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} -

E:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no

file)
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE

/Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32

\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32

\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] "E:\Program Files\rising\Rfw\rfwmain.exe"

-Startup
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1

\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC

Camera
O4 - HKLM\..\Run: [NTdhcp] C:\WINDOWS\System32\NTdhcp.exe
O4 - HKLM\..\Run: [thunder_mini] C:\Program

Files\Sandai\ThunderMini\ThunderMini.exe
O4 - HKLM\..\Run: [hxadsec] C:\WINDOWS\system32\hxadsec.exe
O4 - HKLM\..\Run: [RavTimer] E:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] E:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - E:\Program Files\Sandai

Technologies Inc\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\Program

Files\Sandai Technologies Inc\Thunder\getAllurl.htm
O8 - Extra context menu item: &使用迷你迅雷下载 - C:\Program

Files\Sandai\ThunderMini\geturl.htm
O8 - Extra context menu item: Save豪杰超级解霸V8实时播放 -

e:\Herosoft\HeroV8\MPURLGET.HTM
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) -

res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 收藏此页到ViVi -

http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 新浪搜索 -

http://cha.sina.com.cn/ddt.html
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Program

Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program

Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Program

Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 -

C:\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra button: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} -

E:\Program Files\sina\UC\UC.exe
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-

153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A

-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2

-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} -

E:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-

00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} -

E:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-

9460-4983E5A8AFE6} - E:\Program Files\Tencent\QQ\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E5AD1C9D-9EA4-4FDF-8E66-

FDACAE68ACF0}: NameServer = 202.99.160.68 202.99.168.8
O23 - Service: Macromedia Licensing Service - Unknown owner -

C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia

Licensing.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing

Rising Technology Corporation Limited - e:\program

files\rising\rfw\rfwsrv.exe
gototop
 

修复:
O2 - BHO: URLMonitor Class - {3ED9FFDA-79DB-4B2D-99B7-16EA3C4A3A92} - C:\WINDOWS\System32\hap.dll

O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14} - C:\WINDOWS\System32\winhtp.dll

O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)

O4 - HKLM\..\Run: [NTdhcp] C:\WINDOWS\System32\NTdhcp.exe

O4 - HKLM\..\Run: [hxadsec] C:\WINDOWS\system32\hxadsec.exe

删除文件:

C:\WINDOWS\System32\hap.dll

C:\WINDOWS\System32\winhtp.dll

C:\WINDOWS\System32\msdxm.ocx

C:\WINDOWS\System32\NTdhcp.exe

C:\WINDOWS\system32\hxadsec.exe




gototop
 

怎么跟我遇到的有点像啊???????
gototop
 

谢谢你  花落花又开,已经修好了。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT