楼主: hflcat
收起左侧

求助木马程序 Trojan-Downloader.VBS.Small.bo

[复制链接]
wangjay1980
发表于 2007-3-18 00:38:39 | 显示全部楼层
wangjay1980
发表于 2007-3-18 00:43:05 | 显示全部楼层
是不是只有冰刃才能看见这些病毒文件,你显示所有文件和隐藏文件看看能看见这些文件吗,另外最好在安全模式下删除
hflcat
 楼主| 发表于 2007-3-18 00:43:55 | 显示全部楼层
都删除了,非常感谢。

得到了很多工具,也学到了不少东西
hflcat
 楼主| 发表于 2007-3-18 00:45:00 | 显示全部楼层
原帖由 wangjay1980 于 2007-3-18 00:43 发表
是不是只有冰刃才能看见这些病毒文件,你显示所有文件和隐藏文件看看能看见这些文件吗,另外最好在安全模式下删除


只有冰刃能看见,显示所有文件一直是开着的。

安全模式,等我重启先。
hflcat
 楼主| 发表于 2007-3-18 01:03:37 | 显示全部楼层
现在文件夹都被删除了的,已经重启过了,

不过系统启动后多了个进程

C:\Winnt\system32\internat.exe
是不是有问题
hflcat
 楼主| 发表于 2007-3-18 10:04:06 | 显示全部楼层
现在卡巴还在报C:\WINNT\gz.exe

ICESWORD里查到C:\WINNT\gz.exe  现在是个文件,删除后重启还是会出现
wangjay1980
发表于 2007-3-18 14:43:33 | 显示全部楼层
这个病毒太牛了,难道它是把自己加载到系统的服务里,你在用SRE扫个报告,另外你选冰刃里的SSDT看看,红色的都是那些文件
hflcat
 楼主| 发表于 2007-3-18 14:47:46 | 显示全部楼层

  1. 2007-03-18,14:50:39
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows 2000 Professional Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件

  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <internat.exe><internat.exe>  [(Verified)Microsoft Windows 2000 Publisher]
  17. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  18.     <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
  19.     <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
  20.     <StormCodec_Helper><"D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
  21.     <kav><"D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  22.     <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  23.     <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Windows 2000 Publisher]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  25.     <shell><Explorer.exe>  [(Verified)Microsoft Windows 2000 Publisher]
  26.     <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Windows 2000 Publisher]
  27. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  28.     <WinlogonNotify: klogon><C:\WINNT\system32\klogon.dll>  [Kaspersky Lab]
  29. ==================================
  30. 启动文件夹
  31. [ADSL拨号王]
  32.   <C:\Documents and Settings\y\「开始」菜单\程序\启动\ADSL拨号王.lnk --> C:\PROGRA~1\HelloNet\HelloNet.exe [HelloNet]><N>
  33. ==================================
  34. 服务
  35. [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  36.   <C:\WINNT\system32\Ati2evxx.exe><ATI Technologies Inc.>
  37. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  38.   <"D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  39. [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  40.   <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
  41. ==================================
  42. 驱动程序
  43. [Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
  44.   <system32\drivers\ALCXSENS.SYS><Sensaura>
  45. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
  46.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  47. [ati2mtag / ati2mtag][Running/Manual Start]
  48.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  49. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  50.   <\??\d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
  51. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  52.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  53. [HelloNet PPPoE 虚拟网卡 / BRPPPOE][Running/Manual Start]
  54.   <system32\DRIVERS\brpppoe.sys><N/A>
  55. [SoundFusion(tm) WDM Driver / cwrwdm][Stopped/Manual Start]
  56.   <system32\DRIVERS\cwrwdm.sys><Cirrus Logic Inc.>
  57. [dmboot / dmboot][Stopped/Disabled]
  58.   <System32\drivers\dmboot.sys><VERITAS Software Corp.>
  59. [Logical Disk Manager Driver / dmio][Running/Boot Start]
  60.   <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
  61. [dmload / dmload][Running/Boot Start]
  62.   <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
  63. [SoundFusion(tm) Joystick / gameenum][Stopped/Manual Start]
  64.   <system32\DRIVERS\gameenum.sys><N/A>
  65. [IdeBusDr / IdeBusDr][Running/Boot Start]
  66.   <\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
  67. [Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
  68.   <\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
  69. [kl1 / kl1][Running/Boot Start]
  70.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  71. [klif / klif][Running/System Start]
  72.   <\??\C:\WINNT\system32\drivers\klif.sys><Kaspersky Lab>
  73. [npkcrypt / npkcrypt][Running/Auto Start]
  74.   <\??\E:\Program Files\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  75. [PfModNT / PfModNT][Running/Auto Start]
  76.   <\??\C:\WINNT\system32\PfModNT.sys><Creative Technology Ltd.>
  77. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  78.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  79. [Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  80.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  81. [Sound Blaster AudioPCI Audio Driver (WDM) / sbpci][Stopped/Manual Start]
  82.   <system32\drivers\sbpci.sys><Creative Technology Ltd.>
  83. [TSP / TSP][Stopped/Manual Start]
  84.   <\??\C:\WINNT\system32\drivers\klif.sys><Kaspersky Lab>
  85. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  86.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  87. ==================================
  88. 浏览器加载项
  89. [NavigatMon Class]
  90.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <E:\Program Files\360safe\safemon\safemon.dll, >
  91. [浩方对战平台]
  92.   {0A155D3C-68E2-4215-A47A-E800A446447A} <E:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
  93. [Web反病毒保护]
  94.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  95. [QQ]
  96.   {c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\Program Files\QQ\QQ.EXE, TENCENT>
  97. [FlashGet]
  98.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
  99. [@msdxmLC.dll,-1@2052,电台(&R)]
  100.   {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
  101. [Edit Class]
  102.   {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINNT\system32\CMBEdit.dll, >
  103. [CKAVWebScan Object]
  104.   {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner Pro\kavwebscan.dll, Kaspersky Lab>
  105. [CEditCtrl Object]
  106.   {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\AliEdit.dll, www.alipay.com>
  107. [AxInputControl Class]
  108.   {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINNT\DOWNLO~1\INPUTC~1.DLL, >
  109. [KSHScan Control]
  110.   {ACFE8232-03C5-4AEC-AF5E-42B806724096} <C:\WINNT\system32\kingsoft\ONLINE~1\KSHScan.ocx, kingsoft>
  111. [Shockwave Flash Object]
  112.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  113. [Rising Web Scan Object]
  114.   {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINNT\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
  115. [上传到QQ网络硬盘]
  116.   <E:\Program Files\QQ\AddToNetDisk.htm, N/A>
  117. [使用网际快车下载]
  118.   <C:\Program Files\FlashGet\jc_link.htm, N/A>
  119. [使用网际快车下载全部链接]
  120.   <C:\Program Files\FlashGet\jc_all.htm, N/A>
  121. [添加到QQ自定义面板]
  122.   <E:\Program Files\QQ\AddPanel.htm, N/A>
  123. [添加到QQ表情]
  124.   <E:\Program Files\QQ\AddEmotion.htm, N/A>
  125. [用QQ彩信发送该图片]
  126.   <E:\Program Files\QQ\SendMMS.htm, N/A>
  127. ==================================
  128. 正在运行的进程
  129. [PID: 172][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  130. [PID: 200][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
  131. [PID: 196][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6997]
  132.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  133.     [C:\WINNT\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4110]
  134.     [C:\WINNT\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  135. [PID: 248][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.7035]
  136.     [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
  137. [PID: 260][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.7011]
  138. [PID: 372][C:\WINNT\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4110]
  139.     [C:\WINNT\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2495]
  140. [PID: 460][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
  141. [PID: 484][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.7059]
  142. [PID: 536][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
  143.     [C:\WINNT\System32\unimdm.tsp]  [Microsoft Corporation, 5.00.2195.6601]
  144.     [C:\WINNT\System32\kmddsp.tsp]  [Microsoft Corporation, 5.00.2150.1]
  145.     [C:\WINNT\System32\ndptsp.tsp]  [Microsoft Corporation, 5.00.2143.1]
  146.     [C:\WINNT\System32\ipconf.tsp]  [Microsoft Corporation, 5.00.2143.1]
  147.     [C:\WINNT\System32\h323.tsp]  [Microsoft Corporation, 5.00.2195.6901]
  148. [PID: 960][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
  149.     [C:\WINNT\AppPatch\AcLayers.DLL]  [Microsoft Corporation, 5.00.2195.6717]
  150.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  151.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  152.     [E:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  153.     [C:\Program Files\Microsoft Office\Office10\msohev.dll]  [Microsoft Corporation, 10.0.2609]
  154.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  155. [PID: 992][C:\WINNT\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.24]
  156. [PID: 1160][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5134]
  157.     [C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.5134]
  158.     [C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  [ATI Technologies, Inc., 6.14.10.5134]
  159.     [C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  [ATI Technologies, Inc., 6.14.10.5134]
  160.     [C:\WINNT\system32\DINPUT8.dll]  [Microsoft Corporation, 5.1.2600.881 built by: Lab06_N(mmbuild)         ]
  161. [PID: 1092][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3249]
  162. [PID: 1228][C:\WINNT\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
  163. [PID: 1260][C:\Program Files\HelloNet\HNMainUI.exe]  [, 2, 3, 0, 1]
  164.     [C:\Program Files\HelloNet\HNKernel.dll]  [HelloNet, 2.2.0.1]
  165.     [C:\Program Files\HelloNet\HNUtils.dll]  [, 2, 2, 0, 1]
  166.     [C:\Program Files\HelloNet\HNRes_0804.dll]  [, 2, 2, 0, 1]
  167.     [C:\Program Files\HelloNet\plugins\Diagnose.dll]  [HelloNet, 2.2.0.1]
  168. [PID: 864][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106]
  169.     [E:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  170.     [C:\Program Files\Microsoft Office\Office10\msohev.dll]  [Microsoft Corporation, 10.0.2609]
  171.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  172.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  173.     [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
  174.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  175.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  176.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  177.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
  178.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  179.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  180.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  181.     [C:\WINNT\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  182.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  183.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  184.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  185. [PID: 636][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106]
  186.     [E:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  187.     [C:\Program Files\Microsoft Office\Office10\msohev.dll]  [Microsoft Corporation, 10.0.2609]
  188.     [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
  189.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  190.     [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
  191.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  192.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  193.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  194.     [D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
  195.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  196.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  197.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  198.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
  199.     [d:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
  200.     [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
  201.     [C:\WINNT\system32\msratelc.dll]  [Microsoft Corporation, 6.00.2800.1106]
  202.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  203.     [C:\WINNT\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  204. [PID: 640][E:\q\SpeedSim.exe]  [SpeedSim Developers, 0, 9, 5, 1]
  205.     [C:\WINNT\system32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
  206.     [E:\q\SpeedKernel.dll]  [SpeedSim Developers, 0, 9, 5, 1]
  207. [PID: 2148][E:\SRE\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  208. ==================================
  209. 文件关联
  210. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  211. .EXE  OK. ["%1" %*]
  212. .COM  OK. ["%1" %*]
  213. .PIF  OK. ["%1" %*]
  214. .REG  OK. [regedit.exe "%1"]
  215. .BAT  OK. ["%1" %*]
  216. .SCR  OK. ["%1" /S]
  217. .CHM  OK. ["C:\WINNT\hh.exe" %1]
  218. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  219. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  220. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  221. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  222. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  223. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  224. ==================================
  225. Winsock 提供者
  226. N/A
  227. ==================================
  228. Autorun.inf
  229. N/A
  230. ==================================
  231. HOSTS 文件
  232. 127.0.0.1       localhost
  233. ==================================
  234. API HOOK
  235. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8B25)
  236. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8D67)
  237. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8F0B)
  238. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xB7AF8C49)
  239. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xB7AF8E8F)
  240. ==================================
  241. 隐藏进程
  242. N/A
  243. ==================================
复制代码
hflcat
 楼主| 发表于 2007-3-18 14:51:56 | 显示全部楼层
红色的是3个
C:\WINNT\System32\drivers\klif.sys

d:\program files\Grisoft\AVG Anti-spyware 7.5\guard.sys

kl1.sys

难道他把我的AVG感染了

现在卡8会报2个病毒文件, C:\WINNT\gz.exe  和  C:\WINNT\070116.vbs

但是我在安全模式下用冰刃也找不到这两个文件或者文件夹。

正常模式就会反复报警——》删除——》继续报警

[ 本帖最后由 hflcat 于 2007-3-18 14:56 编辑 ]
wangjay1980
发表于 2007-3-18 15:19:47 | 显示全部楼层
C:\WINDOWS\070116.vbs
C:\WINDOWS\addins\wmi.bat
C:\WINDOWS\addins\main.vbs
C:\WINDOWS\addins\wmi.vbs
C:\WINDOWS\addins\svchost.exe
C:\WINDOWS\addins\Result.txt
看看你有这些文件没有
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 02:59 , Processed in 0.094750 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表