楼主: hflcat
收起左侧

求助木马程序 Trojan-Downloader.VBS.Small.bo

[复制链接]
hflcat
 楼主| 发表于 2007-3-16 22:29:54 | 显示全部楼层
删除了

已删除: 木马程序 Trojan-PSW.Win32.OnLineGames.es 文件: C:\WINNT\gz.exe/PE_Patch/UPack

卡巴还是在报警这个信息。。。是否要重启下重新扫个报告?
wangjay1980
发表于 2007-3-16 22:40:00 | 显示全部楼层
好的
hflcat
 楼主| 发表于 2007-3-16 22:41:10 | 显示全部楼层
  1. 2007-03-16,22:42:23
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows 2000 Professional Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件

  13. 启动项目
  14. 注册表
  15. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Windows 2000 Publisher]
  17.     <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  18.     <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
  19.     <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
  20.     <StormCodec_Helper><"D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
  21.     <kav><"D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  23.     <shell><Explorer.exe>  [(Verified)Microsoft Windows 2000 Publisher]
  24.     <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Windows 2000 Publisher]
  25. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  26.     <WinlogonNotify: klogon><C:\WINNT\system32\klogon.dll>  [Kaspersky Lab]
  27. ==================================
  28. 启动文件夹
  29. [ADSL拨号王]
  30.   <C:\Documents and Settings\y\「开始」菜单\程序\启动\ADSL拨号王.lnk --> C:\PROGRA~1\HelloNet\HelloNet.exe [HelloNet]><N>
  31. ==================================
  32. 服务
  33. [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  34.   <C:\WINNT\system32\Ati2evxx.exe><ATI Technologies Inc.>
  35. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  36.   <"D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  37. [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  38.   <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
  39. ==================================
  40. 驱动程序
  41. [Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
  42.   <system32\drivers\ALCXSENS.SYS><Sensaura>
  43. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
  44.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  45. [ati2mtag / ati2mtag][Running/Manual Start]
  46.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  47. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  48.   <\??\d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
  49. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  50.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  51. [HelloNet PPPoE 虚拟网卡 / BRPPPOE][Running/Manual Start]
  52.   <system32\DRIVERS\brpppoe.sys><N/A>
  53. [SoundFusion(tm) WDM Driver / cwrwdm][Stopped/Manual Start]
  54.   <system32\DRIVERS\cwrwdm.sys><Cirrus Logic Inc.>
  55. [dmboot / dmboot][Stopped/Disabled]
  56.   <System32\drivers\dmboot.sys><VERITAS Software Corp.>
  57. [Logical Disk Manager Driver / dmio][Running/Boot Start]
  58.   <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
  59. [dmload / dmload][Running/Boot Start]
  60.   <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
  61. [SoundFusion(tm) Joystick / gameenum][Stopped/Manual Start]
  62.   <system32\DRIVERS\gameenum.sys><N/A>
  63. [IdeBusDr / IdeBusDr][Running/Boot Start]
  64.   <\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
  65. [Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
  66.   <\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
  67. [kl1 / kl1][Running/Boot Start]
  68.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  69. [klif / klif][Running/System Start]
  70.   <\??\C:\WINNT\system32\drivers\klif.sys><Kaspersky Lab>
  71. [npkcrypt / npkcrypt][Running/Auto Start]
  72.   <\??\E:\Program Files\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  73. [PfModNT / PfModNT][Running/Auto Start]
  74.   <\??\C:\WINNT\system32\PfModNT.sys><Creative Technology Ltd.>
  75. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  76.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  77. [Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  78.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  79. [Sound Blaster AudioPCI Audio Driver (WDM) / sbpci][Stopped/Manual Start]
  80.   <system32\drivers\sbpci.sys><Creative Technology Ltd.>
  81. [TSP / TSP][Stopped/Manual Start]
  82.   <\??\C:\WINNT\system32\drivers\klif.sys><Kaspersky Lab>
  83. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  84.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  85. ==================================
  86. 浏览器加载项
  87. [NavigatMon Class]
  88.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\Program Files\360safe\safemon\safemon.dll, >
  89. [浩方对战平台]
  90.   {0A155D3C-68E2-4215-A47A-E800A446447A} <E:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
  91. [Web反病毒保护]
  92.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  93. [QQ]
  94.   {c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\Program Files\QQ\QQ.EXE, TENCENT>
  95. [FlashGet]
  96.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
  97. [@msdxmLC.dll,-1@2052,电台(&R)]
  98.   {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
  99. [Edit Class]
  100.   {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINNT\system32\CMBEdit.dll, >
  101. [CKAVWebScan Object]
  102.   {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner Pro\kavwebscan.dll, Kaspersky Lab>
  103. [CEditCtrl Object]
  104.   {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\AliEdit.dll, www.alipay.com>
  105. [AxInputControl Class]
  106.   {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINNT\DOWNLO~1\INPUTC~1.DLL, >
  107. [KSHScan Control]
  108.   {ACFE8232-03C5-4AEC-AF5E-42B806724096} <C:\WINNT\system32\kingsoft\ONLINE~1\KSHScan.ocx, kingsoft>
  109. [Shockwave Flash Object]
  110.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  111. [Rising Web Scan Object]
  112.   {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINNT\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
  113. [上传到QQ网络硬盘]
  114.   <E:\Program Files\QQ\AddToNetDisk.htm, N/A>
  115. [使用网际快车下载]
  116.   <C:\Program Files\FlashGet\jc_link.htm, N/A>
  117. [使用网际快车下载全部链接]
  118.   <C:\Program Files\FlashGet\jc_all.htm, N/A>
  119. [添加到QQ自定义面板]
  120.   <E:\Program Files\QQ\AddPanel.htm, N/A>
  121. [添加到QQ表情]
  122.   <E:\Program Files\QQ\AddEmotion.htm, N/A>
  123. [用QQ彩信发送该图片]
  124.   <E:\Program Files\QQ\SendMMS.htm, N/A>
  125. ==================================
  126. 正在运行的进程
  127. [PID: 172][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  128. [PID: 200][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  129. [PID: 196][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6997]
  130.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  131.     [C:\WINNT\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4110]
  132.     [C:\WINNT\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  133. [PID: 248][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.7035]
  134.     [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
  135. [PID: 260][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.7011]
  136. [PID: 368][C:\WINNT\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4110]
  137.     [C:\WINNT\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2495]
  138. [PID: 460][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
  139. [PID: 484][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.7059]
  140. [PID: 536][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
  141.     [C:\WINNT\System32\unimdm.tsp]  [Microsoft Corporation, 5.00.2195.6601]
  142.     [C:\WINNT\System32\kmddsp.tsp]  [Microsoft Corporation, 5.00.2150.1]
  143.     [C:\WINNT\System32\ndptsp.tsp]  [Microsoft Corporation, 5.00.2143.1]
  144.     [C:\WINNT\System32\ipconf.tsp]  [Microsoft Corporation, 5.00.2143.1]
  145.     [C:\WINNT\System32\h323.tsp]  [Microsoft Corporation, 5.00.2195.6901]
  146. [PID: 576][C:\WINNT\system32\MSTask.exe]  [Microsoft Corporation, 4.71.2195.6972]
  147. [PID: 680][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
  148. [PID: 696][C:\WINNT\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4110]
  149.     [C:\WINNT\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2495]
  150. [PID: 952][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
  151.     [C:\WINNT\AppPatch\AcLayers.DLL]  [Microsoft Corporation, 5.00.2195.6717]
  152.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  153.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  154.     [E:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  155.     [C:\Program Files\Microsoft Office\Office10\msohev.dll]  [Microsoft Corporation, 10.0.2609]
  156.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  157. [PID: 1192][C:\WINNT\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.24]
  158. [PID: 1208][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5134]
  159.     [C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.5134]
  160.     [C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  [ATI Technologies, Inc., 6.14.10.5134]
  161.     [C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  [ATI Technologies, Inc., 6.14.10.5134]
  162.     [C:\WINNT\system32\DINPUT8.dll]  [Microsoft Corporation, 5.1.2600.881 built by: Lab06_N(mmbuild)         ]
  163. [PID: 1216][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3249]
  164. [PID: 1304][C:\Program Files\HelloNet\HNMainUI.exe]  [, 2, 3, 0, 1]
  165.     [C:\Program Files\HelloNet\HNKernel.dll]  [HelloNet, 2.2.0.1]
  166.     [C:\Program Files\HelloNet\HNUtils.dll]  [, 2, 2, 0, 1]
  167.     [C:\Program Files\HelloNet\HNRes_0804.dll]  [, 2, 2, 0, 1]
  168.     [C:\Program Files\HelloNet\plugins\Diagnose.dll]  [HelloNet, 2.2.0.1]
  169. [PID: 1028][C:\Documents and Settings\y\桌面\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  170.     [E:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  171.     [C:\Program Files\Microsoft Office\Office10\msohev.dll]  [Microsoft Corporation, 10.0.2609]
  172.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  173.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  174.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  175.     [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
  176.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  177.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  178.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  179.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
  180.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  181.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  182.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  183.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  184.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  185. [PID: 316][E:\SRE\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  186. ==================================
  187. 文件关联
  188. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  189. .EXE  OK. ["%1" %*]
  190. .COM  OK. ["%1" %*]
  191. .PIF  OK. ["%1" %*]
  192. .REG  OK. [regedit.exe "%1"]
  193. .BAT  OK. ["%1" %*]
  194. .SCR  OK. ["%1" /S]
  195. .CHM  OK. ["C:\WINNT\hh.exe" %1]
  196. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  197. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  198. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  199. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  200. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  201. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  202. ==================================
  203. Winsock 提供者
  204. N/A
  205. ==================================
  206. Autorun.inf
  207. N/A
  208. ==================================
  209. HOSTS 文件
  210. 127.0.0.1       localhost
  211. ==================================
  212. API HOOK
  213. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8B25)
  214. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8D67)
  215. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8F0B)
  216. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8C49)
  217. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xB7AF8E8F)
  218. ==================================
  219. 隐藏进程
  220. N/A
  221. ==================================
复制代码


这是重启后新的扫描报告,另外,卡巴还是在报警
计算机重启后删除: 木马程序 Trojan-PSW.Win32.OnLineGames.es 文件: C:\WINNT\gz.exe/PE_Patch/UPack
感谢斑竹指点,同时能否告之哪里有SRE扫描分析教程,也想学习一下。
wangjay1980
发表于 2007-3-16 23:10:10 | 显示全部楼层
你可以用哪个删除工具删除C:\WINNT\gz.exe/PE_Patch/UPack,另外把桌面的IE删除。
hflcat
 楼主| 发表于 2007-3-16 23:24:08 | 显示全部楼层
C:\WINNT\gz.exe 可以被删除,但是会自动再生成

C:\WINNT\gz.exe/PE_Patch/UPack  目标文件不存在

现在卡巴一直在提示这个

计算机重启后删除: 木马程序 Trojan-PSW.Win32.OnLineGames.es 文件: C:\WINNT\gz.exe/PE_Patch/UPack

另外桌面IE删除了我在哪启动IE呢

[ 本帖最后由 hflcat 于 2007-3-16 23:32 编辑 ]
wangjay1980
发表于 2007-3-16 23:28:42 | 显示全部楼层
没事,可以自己在放个快捷方式
wangjay1980
发表于 2007-3-16 23:31:40 | 显示全部楼层
你有冰刃吗,用冰刃打开C:\WINNT\下看看有没有gz.exe
hflcat
 楼主| 发表于 2007-3-16 23:36:30 | 显示全部楼层
没有这个文件

有gz.exe文件夹,不过是空的。

另外,我只有桌面这个IE可以启动-。- 在哪可以重新设置快界方式?

[ 本帖最后由 hflcat 于 2007-3-16 23:40 编辑 ]
wangjay1980
发表于 2007-3-16 23:45:39 | 显示全部楼层
你去这里看看是不是有两个MSTask.exeC:\WINNT\system32\MSTask.exe。
hflcat
 楼主| 发表于 2007-3-16 23:47:37 | 显示全部楼层
只有一个,另外一个是MSTASK.DLL
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-22 21:02 , Processed in 0.086702 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表