瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 有人借助新病毒“移动加密”进行网络敲诈,怎么办。

12   1  /  2  页   跳转

有人借助新病毒“移动加密”进行网络敲诈,怎么办。

有人借助新病毒“移动加密”进行网络敲诈,怎么办。

今天不知怎么回事,电脑上所有文件被一个叫做《移动加密》的软件加密。此软件通过网络自动安装在我的电脑上,加密了除C盘以外的其它盘上的所有文件,需要输入密码才能打开,但是我不知道密码呀,怎么办呢?他提示说:非法解密将摧毁所有数据!!怎么办呢?急呀,里面是我所有的文件,含非常非常重要的工作文件!!根据他留下来的联系方式,一个客服QQ,他说需要他们技术人员来解密,敲诈我300元钱!我痛恨这种网络敲诈行为,但是又无计可施,故在此请求哪位高人指点密津,卸载这个可恶的软件,还我文件,多谢啦!!
最后编辑2006-02-06 10:32:13
分享到:
gototop
 

到底这种移动加密是什么病毒呀,有哪位高人有办法?
gototop
 

已经报警了,但是警察不管,怎么办呀?这个社会真是没有天理王法了!:((((
555555555555555……
gototop
 

保存了日志,如下:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ vptraySymantec AntiVirusSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\vptray.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ LDVP Shell ExtensionsSymantec AntiVirusSymantec Corporationc:\program files\common files\symantec shared\ssc\vpshell2.dll

+ PicaViewPicaView 系统扩展 DLLACD Systems, Ltd.c:\program files\acdsee\picaview.dll

+ PowerWord ExplorerBarPowerWord Web Dictionary Engine金山软件股份有限公司d:\program files\kingsoft\powerword 2003\xdictexb.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\program files\tencent\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe

+ JUJU猫File not found: http://www.jujumao.net

+ 豪杰超级解霸V8Hero Super Player V8herosoftc:\herosoft\herov8\sthsdvd.exe

+ 腾讯QQQQTENCENTd:\program files\tencent\qq\qq.exe

HKLM\System\CurrentControlSet\Services

+ DefWatchVirus Definition DaemonSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\defwatch.exe

+ GrayPigeonServerc:\windows\nonfig.exe

+ Norton AntiVirus Server为 Symantec Client Security 提供实时病毒扫描、报告和管理功能。Symantec Corporationc:\program files\symantec_client_security\symantec antivirus\rtvscan.exe

HKLM\System\CurrentControlSet\Services

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ AliIdeFile not found: System32\DRIVERS\aliide.sys

+ CA561Universal Serial Bus Camera DriverSPc:\windows\system32\drivers\spca561.sys

+ CKG005File not found: C:\WINDOWS\TEMP\hk06.sys6kit8ul.sys

+ CmdIdeCMD PCI IDE Bus DriverCMD Technology, Inc.c:\windows\system32\drivers\cmdide.sys

+ ialmIntel Graphics Miniport DriverIntel Corporationc:\windows\system32\drivers\ialmnt5.sys

+ MegaIDELSI MegaRAID IDE DriverLSI Logic Corporation.c:\windows\system32\drivers\megaide.sys

+ NAVAPAutoProtectSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\navap.sys

+ NAVAPELNAVAPELSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\navapel.sys

+ NAVENGAV EngineSymantec Corporationc:\program files\common files\symantec shared\virusdefs\20060118.007\naveng.sys

+ NAVEX15AV EngineSymantec Corporationc:\program files\common files\symantec shared\virusdefs\20060118.007\navex15.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ SymEventSymantec Event LibrarySymantec Corporationc:\program files\symantec\symevent.sys

+ XBBO99File not found: C:\WINDOWS\TEMP\fmizlqdh.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ igfxcuiigfxsrvc ModuleIntel Corporationc:\windows\system32\igfxsrvc.dll

+ NavLogonc:\windows\system32\navlogon.dll

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD Tcpip [RAW/IP]c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [TCP/IP]c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [UDP/IP]c:\windows\system32\tcpipdog0.dll

+ RSVP TCP Service Providerc:\windows\system32\tcpipdogr0.dll

+ RSVP UDP Service Providerc:\windows\system32\tcpipdogr0.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ HPLJ1020LMSpooler Language Monitor for HP LaserJet Series 1020/2600Zenographics, Inc.c:\windows\system32\zlhp1020.dll

gototop
 

请问高人分析一下,到底怎么解决这个问题,急死了,用不了以前的文件!5555555555


多谢了!
gototop
 

上面的方法不行,现在重新扫描一个日志上来,请分析解决一下:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ vptraySymantec AntiVirusSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\vptray.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ LDVP Shell ExtensionsSymantec AntiVirusSymantec Corporationc:\program files\common files\symantec shared\ssc\vpshell2.dll

+ PicaViewPicaView 系统扩展 DLLACD Systems, Ltd.c:\program files\acdsee\picaview.dll

+ PowerWord ExplorerBarPowerWord Web Dictionary Engine金山软件股份有限公司d:\program files\kingsoft\powerword 2003\xdictexb.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\program files\tencent\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe

+ JUJU猫File not found: http://www.jujumao.net

+ 豪杰超级解霸V8Hero Super Player V8herosoftc:\herosoft\herov8\sthsdvd.exe

+ 腾讯QQQQTENCENTd:\program files\tencent\qq\qq.exe

HKLM\System\CurrentControlSet\Services

+ DefWatchVirus Definition DaemonSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\defwatch.exe

+ Norton AntiVirus Server为 Symantec Client Security 提供实时病毒扫描、报告和管理功能。Symantec Corporationc:\program files\symantec_client_security\symantec antivirus\rtvscan.exe

HKLM\System\CurrentControlSet\Services

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ AliIdeFile not found: System32\DRIVERS\aliide.sys

+ CA561Universal Serial Bus Camera DriverSPc:\windows\system32\drivers\spca561.sys

+ CKG005File not found: C:\WINDOWS\TEMP\hk06.sys6kit8ul.sys

+ CmdIdeCMD PCI IDE Bus DriverCMD Technology, Inc.c:\windows\system32\drivers\cmdide.sys

+ ialmIntel Graphics Miniport DriverIntel Corporationc:\windows\system32\drivers\ialmnt5.sys

+ MegaIDELSI MegaRAID IDE DriverLSI Logic Corporation.c:\windows\system32\drivers\megaide.sys

+ NAVAPAutoProtectSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\navap.sys

+ NAVAPELNAVAPELSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\navapel.sys

+ NAVENGAV EngineSymantec Corporationc:\program files\common files\symantec shared\virusdefs\20060118.007\naveng.sys

+ NAVEX15AV EngineSymantec Corporationc:\program files\common files\symantec shared\virusdefs\20060118.007\navex15.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ SymEventSymantec Event LibrarySymantec Corporationc:\program files\symantec\symevent.sys

+ XBBO99File not found: C:\WINDOWS\TEMP\fmizlqdh.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ igfxcuiigfxsrvc ModuleIntel Corporationc:\windows\system32\igfxsrvc.dll

+ NavLogonc:\windows\system32\navlogon.dll

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD Tcpip [RAW/IP]c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [TCP/IP]c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [UDP/IP]c:\windows\system32\tcpipdog0.dll

+ RSVP TCP Service Providerc:\windows\system32\tcpipdogr0.dll

+ RSVP UDP Service Providerc:\windows\system32\tcpipdogr0.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ HPLJ1020LMSpooler Language Monitor for HP LaserJet Series 1020/2600Zenographics, Inc.c:\windows\system32\zlhp1020.dll


gototop
 

发布一个刷新后扫描的日志上来供高人分析:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ vptraySymantec AntiVirusSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\vptray.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ LDVP Shell ExtensionsSymantec AntiVirusSymantec Corporationc:\program files\common files\symantec shared\ssc\vpshell2.dll

+ PicaViewPicaView 系统扩展 DLLACD Systems, Ltd.c:\program files\acdsee\picaview.dll

+ PowerWord ExplorerBarPowerWord Web Dictionary Engine金山软件股份有限公司d:\program files\kingsoft\powerword 2003\xdictexb.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\program files\tencent\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe

+ JUJU猫File not found: http://www.jujumao.net

+ 豪杰超级解霸V8Hero Super Player V8herosoftc:\herosoft\herov8\sthsdvd.exe

+ 腾讯QQQQTENCENTd:\program files\tencent\qq\qq.exe

HKLM\System\CurrentControlSet\Services

+ DefWatchVirus Definition DaemonSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\defwatch.exe

+ Norton AntiVirus Server为 Symantec Client Security 提供实时病毒扫描、报告和管理功能。Symantec Corporationc:\program files\symantec_client_security\symantec antivirus\rtvscan.exe

HKLM\System\CurrentControlSet\Services

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ AliIdeFile not found: System32\DRIVERS\aliide.sys

+ CA561Universal Serial Bus Camera DriverSPc:\windows\system32\drivers\spca561.sys

+ CKG005File not found: C:\WINDOWS\TEMP\hk06.sys6kit8ul.sys

+ CmdIdeCMD PCI IDE Bus DriverCMD Technology, Inc.c:\windows\system32\drivers\cmdide.sys

+ ialmIntel Graphics Miniport DriverIntel Corporationc:\windows\system32\drivers\ialmnt5.sys

+ MegaIDELSI MegaRAID IDE DriverLSI Logic Corporation.c:\windows\system32\drivers\megaide.sys

+ NAVAPAutoProtectSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\navap.sys

+ NAVAPELNAVAPELSymantec Corporationc:\program files\symantec_client_security\symantec antivirus\navapel.sys

+ NAVENGAV EngineSymantec Corporationc:\program files\common files\symantec shared\virusdefs\20060118.007\naveng.sys

+ NAVEX15AV EngineSymantec Corporationc:\program files\common files\symantec shared\virusdefs\20060118.007\navex15.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ SymEventSymantec Event LibrarySymantec Corporationc:\program files\symantec\symevent.sys

+ XBBO99File not found: C:\WINDOWS\TEMP\fmizlqdh.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ igfxcuiigfxsrvc ModuleIntel Corporationc:\windows\system32\igfxsrvc.dll

+ NavLogonc:\windows\system32\navlogon.dll

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD Tcpip [RAW/IP]c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [TCP/IP]c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [UDP/IP]c:\windows\system32\tcpipdog0.dll

+ RSVP TCP Service Providerc:\windows\system32\tcpipdogr0.dll

+ RSVP UDP Service Providerc:\windows\system32\tcpipdogr0.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ HPLJ1020LMSpooler Language Monitor for HP LaserJet Series 1020/2600Zenographics, Inc.c:\windows\system32\zlhp1020.dll

gototop
 

回复:第10楼,genuinechen 

仔细拜读了您发的网址,那上面好像没有什么解决方法呀?问题依旧,打不开文件夹!:((
gototop
 

斑竹在吗?我在线等着呢?请尽快帮我解决一下吧,大过年的也让我好好过过年吧,拜托拜托了!
gototop
 

我的电脑里面有很多重要的文件,不能格掉呀,又拷不出文件来,怎么办呀?急!!急!!急!!急!!急!!急!!急!!急!!急!!急!!急!!急!!急!!
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT