瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我电脑里的木马是否被彻底清除?[付日志]

1   1  /  1  页   跳转

我电脑里的木马是否被彻底清除?[付日志]

我电脑里的木马是否被彻底清除?[付日志]

2007-04-26,22:16:55

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional  (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <kav><"E:\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
    <ats><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe asp.exe>  []
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{2133B3FD-315E-4523-BD1A-22F723DFBCA3}><C:\WINDOWS\System32\jpqpri.dll>  []

==================================
启动文件夹
N/A

==================================
服务
[A7481BB2 / A7481BB2][Stopped/Auto Start]
  <C:\WINDOWS\System32\A7481BB2.EXE -service><Microsoft Corporation>
[卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  <E:\Kaspersky Anti-Virus 6.0\avp.exe -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IMAPI CD-Burning COM Service / ImapiService][Stopped/Manual Start]
  <C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Windows ppej RunThem / ppej][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\kkze\uujo.dll><N/A>
[WebPrint / WebPrint][Stopped/Auto Start]
  <c:\windows\system32\webprint.exe><Microsoft Corporation>

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[biiuke5 / biiuke52][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\biiuke52.sys><Microsoft Corporation>
[Bluetooth Audio Service / BlueletAudio][Stopped/Manual Start]
  <System32\DRIVERS\blueletaudio.sys><IVT Corporation>
[Bluetooth PAN Network Adapter / BT][Stopped/Manual Start]
  <System32\DRIVERS\btnetdrv.sys><IVT Corporation>
[Bluetooth HID Enumerator / BTHidEnum][Stopped/Manual Start]
  <System32\DRIVERS\vbtenum.sys><N/A>
[Bluetooth HID Manager Service / BTHidMgr][Running/Boot Start]
  <\SystemRoot\System32\Drivers\BTHidMgr.sys><IVT Corporation>
[kl1 / kl1][Running/Boot Start]
  <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
  <\??\C:\WINDOWS\System32\drivers\klif.sys><Kaspersky Lab>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\E:\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[vbhequ44 / vbhequ44][Stopped/Boot Start]
  <\SystemRoot\system32\\drivers\\system32\\drivers\\%s.sys.sys><N/A>
[Virtual Serial port driver / VComm][Stopped/Manual Start]
  <System32\DRIVERS\VComm.sys><IVT Corporation>
[Bluetooth VComm Manager Service / VcommMgr][Stopped/Manual Start]
  <System32\Drivers\VcommMgr.sys><IVT Corporation>
[WINIO / WINIO][Stopped/Manual Start]
  <\??\G:\winio.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
最后编辑2007-04-26 22:50:41
分享到:
gototop
 

浏览器加载项
[浩方对战平台]
  {0A155D3C-68E2-4215-A47A-E800A446447A} <E:\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <E:\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[NetAnts]
  {57E91B47-F40A-11D1-B792-444553540000} <C:\PROGRA~1\NETANTS\NetAnts.exe,  >
[iTrusPTA Class]
  {1E0DFFCF-27FF-4574-849B-55007349FEDA} <C:\WINDOWS\System32\aliedit\pta.dll, >
[AxInputControl Class]
  {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[WangWangObj Class]
  {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <E:\淘宝旺旺\WangWangX4.dll, 阿里软件(中国)有限公司>
[&Download by NetAnts]
  <C:\PROGRA~1\NETANTS\NAGet.htm, N/A>
[&使用BitComet下载]
  <res://E:\bt 8.4\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
  <res://E:\bt 8.4\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
  <res://E:\bt 8.4\BitComet.exe/AddVideo.htm, N/A>
[Download &All by NetAnts]
  <C:\PROGRA~1\NETANTS\NAGetAll.htm, N/A>

==================================
正在运行的进程
[PID: 484][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 624][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 636][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 812][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 864][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 960][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 976][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1076][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\CNMLM52.DLL]  [CANON INC., 1.70.2.2]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD52.DLL]  [CANON INC., 1.70.2.2]
[PID: 1280][C:\WINDOWS\Explorer.exe]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\jpqpri.dll]  [N/A, ]
    [C:\WINDOWS\System32\javascript.dll]  [, 1.1.1.222]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [E:\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [E:\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [e:\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [E:\WinRAR\rarext.dll]  [N/A, ]
    [E:\Kaspersky Anti-Virus 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Office2003\Microsoft Office 2003 Sp2〖精简免安装绿色版〗\Office\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 1364][C:\WINDOWS\System32\SVCHOST.EXE ]  [b, 1.00]
    [C:\WINDOWS\System32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9237]
[PID: 1360][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2056][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
    [E:\Office2003\Microsoft Office 2003 Sp2〖精简免安装绿色版〗\Office\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [E:\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [E:\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [e:\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1496][E:\bt 8.4\BitComet.exe]  [www.BitComet.com, 0.84]
    [E:\bt 8.4\dbghelp.dll]  [Microsoft Corporation, 6.3.0011.3 (DbgBuild.040120-1256)]
    [C:\WINDOWS\System32\jpqpri.dll]  [N/A, ]
    [E:\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
[PID: 1376][E:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF02A7B25)
RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF02A7D67)
RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF02A7F0B)
RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF02A7C49)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF02A7E8F)

==================================
隐藏进程
N/A
gototop
 





在桌面建立一个文件夹,再用WinRAR工具(即开始-->所有程序里的WinRAR)打开WinRAR-->点“查找”在磁盘和文件夹选 C: 。找到文件(或文件相关的程序),然后按解压到,选桌面刚建的文件夹,然后确定,然后等所有操作做完后再将那个文件夹压缩加密码123(即高级-->设置密码)给我,我的QQ是397005089或者油箱也行wuduyouli@yahoo.com.cn要找的文件如下:
C:\WINDOWS\System32\A7481BB2.EXE
c:\windows\system32\webprint.exe
C:\WINDOWS\System32\SVCHOST.EXE
==============================================================================
关闭所有正在使用的应用程序包括QQ等等
然后关闭系统还原(WIN2000可以忽略):按我的电脑右键的属性点系统还原,在所有驱动器上关闭系统还原 打勾。[等所有操作完成后再去打开]
用ATF清理工具点这里下载http://hzqedison.mm9mm.com/hanhua/ATF-Cleaner-cn.exe,在全选那打勾,然后点立即清理
然后按照我以下的方法做:
==============================================================================
使用XDelBox点这里下载http://www.i170.com/Attach/51FD704F-C0BD-41E7-B0E9-60673A888FD6
运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
复制以下所有要删除的文件路径,然后在"在待删除文件列表"下空白地方按右键选"从剪贴板导入",然后勾选"抑制再生",对着要删除的文件上点击右键,选择立刻重启删除:
C:\WINDOWS\System32\jpqpri.dll
C:\WINDOWS\System32\asp.exe(有就删除没有就忽略)
C:\WINDOWS\asp.exe(有就删除没有就忽略)
C:\WINDOWS\System32\A7481BB2.EXE
C:\PROGRA~1\kkze\uujo.dll
c:\windows\system32\webprint.exe
C:\WINDOWS\System32\SVCHOST.EXE
==============================================================================
等XDelBox杀完后去安全模式进行如下操作(重启电脑 不断按F8 然后选安全模式)进不了安全模式,可以在SREng中 点系统修复 --> 点高级修复,再点修复安全模式
==============================================================================
用工具 SREng 删除如下各项
在SREng中 点 启动项目 --> 注册表  进入后 用鼠标左键在对应要修复的项上单击 然后点击"删除"
  删除如下项目:
<run><> [N/A](有就删除没有就忽略)
<ats><> [N/A]
编辑<shell><Explorer.exe asp.exe> []为<shell><Explorer.exe>
<{2133B3FD-315E-4523-BD1A-22F723DFBCA3}><C:\WINDOWS\System32\jpqpri.dll> []
==============================================================================
在SERng中 点 启动项目 --> 服务 --> Win32服务应用程序 进入后(勾选 隐藏已认证的微软项目),用鼠标左键在对应要修复的项上单击 然后点“删除服务”,再点“设置”按钮即可(注意到最后弹出的窗口中要点 “NO 否”才是确认删除服务。)
删除如下项目:
[A7481BB2 / A7481BB2][Stopped/Auto Start]
<C:\WINDOWS\System32\A7481BB2.EXE -service><Microsoft Corporation>
[Windows ppej RunThem / ppej][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\kkze\uujo.dll><N/A>
[WebPrint / WebPrint][Stopped/Auto Start]
<c:\windows\system32\webprint.exe><Microsoft Corporation>

==============================================================================
在SERng中 点 启动项目 --> 服务 --> 驱动程序 进入后 (勾选 隐藏已认证的微软项目),用鼠标左键在对应要修复的项上单击 然后点“设置” 按钮即可(注意到最后弹出的窗口中要点 “NO 否”才是确认删除驱动。)[注:有关可疑驱动如果你不知道的话建议删除,删除不了可以把类型设置为disabled ]
删除如下项目:
[vbhequ44 / vbhequ44][Stopped/Boot Start]
<\SystemRoot\system32\\drivers\\system32\\drivers\\%s.sys.sys><N/A>

==============================================================================
在SREng中 点系统修复 --> 点Windows Shell/IE ,勾全选,点“修复”
不建议使用绿色软件
==============================================================================
以上步骤做完就重启电脑,然后如果安装了QQ的话就重装QQ(先卸载了,再安装),再用WINDOWS 清理助手点这里下载http://www.arswp.com/download/arswp/arswp.rar和恶意软件清理助手点这里下载http://www.crsky.com/soft/6251.html杀恶意软件,再升级杀毒软件全盘杀毒

                                                       
                                                                        分  析:無毒侑禮
                                                                        时 间:2007-4-26
                                                                          QQ:397005089
                                                              E-mail:wuduyouli@yahoo.com.cn




gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT