查看: 3250|回复: 10
收起左侧

中了一个“手机百宝箱”的病毒,求救

[复制链接]
我不告诉你
发表于 2007-4-6 15:58:27 | 显示全部楼层 |阅读模式

报告

报告
这个病毒怎样除啊

[ 本帖最后由 我不告诉你 于 2007-4-7 09:12 编辑 ]
wangjay1980
发表于 2007-4-6 17:19:07 | 显示全部楼层
用SRE扫个报告
我不告诉你
 楼主| 发表于 2007-4-7 09:45:08 | 显示全部楼层

报告



[ 本帖最后由 我不告诉你 于 2007-4-7 10:31 编辑 ]
一天一天过
发表于 2007-4-7 10:00:10 | 显示全部楼层
把整个的日志内容复制帖上来,不要发图啊;
注册表第三行的项目有问题,这项目删除后清理临时文件夹,最好到安全模式下
我不告诉你
 楼主| 发表于 2007-4-7 10:09:01 | 显示全部楼层

我回复

  1. 2007-04-07,08:45:35

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\windows\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17.     <win><C:\WINDOWS\Temp\serlass.exe>  []
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <run><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <NvCplDaemon><RUNDLL32.EXE   是这一个行要在安全模式注册表下删除吗? C:\windows\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Publisher]
  22.     <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  23.     <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd>  [N/A]
  24.     <SyGateManager><C:\Program Files\SyGate\SHN\Sygate.exe>  [赛格特(Sygate)技术有限公司]
  25.     <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
  26.     <Vistadrv><C:\WINDOWS\Vista\systool\Vistadrive\vsdrv.exe>  []
  27.     <Zone Labs Client><C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe>  [(Verified)Check Point Software Technologies Inc.]
  28.     <硬盘空间状态><C:\windows\Vista\systool\Vistadrive\vsdrv.exe>  []
  29.     <鼠标点击特效><C:\windows\Vista\systool\UberIcon\UberIcon Manager.exe>  []
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  31.     <shell><Explorer.exe>  [(Verified)]
  32.     <Userinit><C:\windows\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  33. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  34.     <AppInit_DLLs><>  [N/A]
  35. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  36.     <UIHost><logonui.exe>  [(Verified)]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  38.     <WPDShServiceObj><C:\windows\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\System Safety Monitor]
  40.     <WinlogonNotify: System Safety Monitor><SSMWinlogonEx.dll>  [(Verified)System Safety Limited]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\themeui]
  42.     <WinlogonNotify: themeui><cryptsvc.dIl>  []
  43. [HKEY_CURRENT_USER\Control Panel\Desktop]
  44.     <SCRNSAVE.EXE><C:\WINDOWS\system32\夜光时钟.SCR>  []

  45. ==================================
  46. 启动文件夹
  47. [cmd]
  48.   <C:\Documents and Settings\yang_aimin2000\「开始」菜单\程序\启动\cmd.lnk --> C:\WINDOWS\Temp\serlass.exe [N/A]><N>
  49. [RegVac]
  50.   <C:\Documents and Settings\yang_aimin2000\「开始」菜单\程序\启动\RegVac.lnk --> C:\PROGRA~1\RegVac\regvac.exe [N/A]><N>

  51. ==================================
  52. 服务
  53. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  54.   <C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
  55. [卡巴斯基反病毒 6.0 / AVP][Running/Auto Start]
  56.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  57. [ Cryptographic Server / CryptographicServer][Stopped/Auto Start]
  58.   <><N/A>
  59. [Human Interface Device Access / HidServ][Stopped/Disabled]
  60.   <C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  61. [InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  62.   <"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"><Macrovision Corporation>
  63. [IEAgent service / IEAgent][Stopped/Auto Start]
  64.   <"C:\windows\system32\ieagent.exe"><>
  65. [StarWind iSCSI Service / StarWindService][Running/Auto Start]
  66.   <C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
  67. [TrueVector Internet Monitor / vsmon][Running/Auto Start]
  68.   <C:\WINDOWS\system32\ZONELABS\vsmon.exe -service><Zone Labs, LLC>

  69. ==================================
  70. 驱动程序
  71. [100133 / 100133][Stopped/Boot Start]
  72.   <\SystemRoot\System32\drivers\100133.sys><N/A>
  73. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  74.   <system32\drivers\ac97intc.sys><Intel Corporation>
  75. [AliIde / AliIde][Running/Boot Start]
  76.   <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
  77. [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  78.   <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
  79. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  80.   <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
  81. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  82.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  83. [bzusyn2 / bzusyn25][Stopped/Boot Start]
  84.   <\SystemRoot\System32\DRIVERS\bzusyn25.sys><N/A>
  85. [ccefchhg / ccefchhg][Stopped/Boot Start]
  86.   <\SystemRoot\system32\drivers\ccefchhg.sys><N/A>
  87. [CmdIde / CmdIde][Running/Boot Start]
  88.   <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
  89. [C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  90.   <system32\drivers\cmuda.sys><C-Media Inc>
  91. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  92.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  93. [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  94.   <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
  95. [iycown3 / iycown37][Stopped/Boot Start]
  96.   <\SystemRoot\System32\DRIVERS\iycown37.sys><N/A>
  97. [kl1 / kl1][Running/Boot Start]
  98.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  99. [klif / klif][Running/System Start]
  100.   <\??\C:\windows\system32\drivers\klif.sys><Kaspersky Lab>
  101. [mmelhn3 / mmelhn36][Stopped/Boot Start]
  102.   <\SystemRoot\System32\DRIVERS\mmelhn36.sys><N/A>
  103. [npkcrypt / npkcrypt][Running/Auto Start]
  104.   <\??\C:\Program Files\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
  105. [nv / nv][Running/Manual Start]
  106.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  107. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  108.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  109. [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  110.   <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
  111. [System Safety Monitor 2.0 Core Engine / safemon][Running/Boot Start]
  112.   <\SystemRoot\system32\drivers\safemon.sys><System Safety Limited>
  113. [sdetnv6 / sdetnv63][Stopped/Disabled]
  114.   <System32\DRIVERS\sdetnv63.sys><N/A>
  115. [Secdrv / Secdrv][Stopped/Manual Start]
  116.   <system32\DRIVERS\secdrv.sys><N/A>
  117. [sptd / sptd][Running/Boot Start]
  118.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  119. [TAP-Win32 Adapter V8 / tap0801][Running/Manual Start]
  120.   <system32\DRIVERS\tap0801.sys><The OpenVPN Project>
  121. [TSP / TSP][Stopped/Manual Start]
  122.   <\??\C:\windows\system32\drivers\klif.sys><Kaspersky Lab>
  123. [usb8028 / usb8028][Running/System Start]
  124.   <system32\drivers\usb8028.sys><N/A>
  125. [usb8028x / usb8028x][Running/System Start]
  126.   <system32\drivers\usb8028x.sys><Windows System Internal>
  127. [vaxDLb / vaxDLb][Running/Boot Start]
  128.   <\SystemRoot\system32\DRIVERS\vaxDLb.sys><>
  129. [vaxDLs / vaxDLs][Running/Boot Start]
  130.   <\SystemRoot\System32\Drivers\vaxDLs.sys><>
  131. [ViaIde / ViaIde][Running/Boot Start]
  132.   <\SystemRoot\system32\DRIVERS\viaidexp.sys><VIA Technologies, Inc.>
  133. [Virtual PC Application Services / VPCAppSv][Running/Auto Start]
  134.   <system32\DRIVERS\VPCAppSv.sys><Connectix Corporation>
  135. [vsdatant / vsdatant][Running/System Start]
  136.   <System32\vsdatant.sys><Zone Labs, LLC>
  137. [SyGate for NT, WG1N / WG1N][Running/Auto Start]
  138.   <\SystemRoot\SYSTEM32\Drivers\WG1N.sys><Sygate Technologies, Inc.>
  139. [SyGate for NT, WG2N / WG2N][Running/Auto Start]
  140.   <\SystemRoot\SYSTEM32\Drivers\WG2N.sys><Sygate Technologies, Inc.>
  141. [SyGate for NT, wg4n / wg4n][Running/Auto Start]
  142.   <\SystemRoot\SYSTEM32\Drivers\wg4n.sys><Sygate Technologies, Inc.>
  143. [SyGate for NT, wg5n / wg5n][Running/Auto Start]
  144.   <\SystemRoot\SYSTEM32\Drivers\wg5n.sys><Sygate Technologies, Inc.>
  145. [SyGate for NT, wg6n / wg6n][Running/Auto Start]
  146.   <\SystemRoot\SYSTEM32\Drivers\wg6n.sys><Sygate Technologies, Inc.>
  147. [SyGate for NT, Wsdrv / Wsdrv][Running/Boot Start]
  148.   <\SystemRoot\\SystemRoot\SYSTEM32\Drivers\Wsdrv.sys><N/A>

  149. ==================================
  150. 浏览器加载项
  151. [快速搜索]
  152.   {BF5DC4AE-258C-43d5-9D80-1F7ACD734DD8} <C:\WINDOWS\Temp\sjbbx.exe, N/A>
  153. [Shockwave Flash Object]
  154.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  155. [上传到QQ网络硬盘]
  156.   <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
  157. [使用迅雷下载]
  158.   <, N/A>
  159. [使用迅雷下载全部链接]
  160.   <, N/A>
  161. [导出到 Microsoft Office Excel(&X)]
  162.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  163. [添加到QQ自定义面板]
  164.   <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
  165. [添加到QQ表情]
  166.   <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
  167. [用QQ彩信发送该图片]
  168.   <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
  169. [访问通用网址]
  170.   <, N/A>

  171. ==================================
  172. 正在运行的进程
  173. [PID: 1000][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  174. [PID: 692][C:\windows\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  175.     [C:\windows\system32\WBJJU.IME]  [北京六合源软件技术有限公司, 2, 8, 1, 0]
  176.     [C:\windows\system32\WbCodeU.dll]  [, 2, 8, 1, 0]
  177.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
  178.     [C:\windows\Vista\systool\UberIcon\UberIcon.dll]  [N/A, ]
  179. [PID: 572][C:\Program Files\SyGate\SHN\Sygate.exe]  [赛格特(Sygate)技术有限公司, 4.5.850.1]
  180.     [C:\Program Files\SyGate\SHN\AREdt.dll]  [, 1, 0, 0, 1]
  181.     [C:\Program Files\Opera\Opera.dll]  [Opera Software, 8746]
  182.     [C:\windows\Vista\systool\UberIcon\UberIcon.dll]  [N/A, ]
  183.     [C:\windows\system32\WBJJU.IME]  [北京六合源软件技术有限公司, 2, 8, 1, 0]
  184.     [C:\windows\system32\WbCodeU.dll]  [, 2, 8, 1, 0]
  185. [PID: 2780][E:\TDDownload\软件\清洁类\WINDOWS 清理助手\WINDOWS 清理助手\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  186.     [C:\windows\Vista\systool\UberIcon\UberIcon.dll]  [N/A, ]
  187.     [C:\windows\system32\WBJJU.IME]  [北京六合源软件技术有限公司, 2, 8, 1, 0]
  188.     [C:\windows\system32\WbCodeU.dll]  [, 2, 8, 1, 0]
  189.     [C:\windows\Vista\systool\UberIcon\UberIcon.dll]  [N/A, ]
  190.     [C:\windows\system32\WBJJU.IME]  [北京六合源软件技术有限公司, 2, 8, 1, 0]
  191.     [C:\windows\system32\WbCodeU.dll]  [, 2, 8, 1, 0]

  192. ==================================
  193. 文件关联
  194. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  195. .EXE  OK. ["%1" %*]
  196. .COM  OK. ["%1" %*]
  197. .PIF  OK. ["%1" %*]
  198. .REG  OK. [regedit.exe "%1"]
  199. .BAT  OK. ["%1" %*]
  200. .SCR  OK. ["%1" /S]
  201. .CHM  OK. ["C:\windows\hh.exe" %1]
  202. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  203. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  204. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  205. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  206. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  207. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  208. ==================================
  209. Winsock 提供者
  210. N/A

  211. ==================================
  212. Autorun.inf
  213. N/A

  214. ==================================
  215. HOSTS 文件
  216. N/A

  217. ==================================
  218. API HOOK
  219. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF7CE0AF0)
  220. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF7CE0CD0)
  221. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF7CE0E30)
  222. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF7CE0BE0)
  223. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF7CE0DE0)

  224. ==================================
  225. 隐藏进程
  226. N/A

  227. ==================================
复制代码
对不起头一次做这件事,谢谢版主

[ 本帖最后由 我不告诉你 于 2007-4-7 10:28 编辑 ]
我不告诉你
 楼主| 发表于 2007-4-7 10:30:12 | 显示全部楼层

回复

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <NvCplDaemon><RUNDLL32.EXE   是这一个行要在安全模式注册表下删除吗?
wangjay1980
发表于 2007-4-7 13:15:24 | 显示全部楼层
<win><C:\WINDOWS\Temp\serlass.exe>&#
[cmd]
  <C:\Documents and Settings\yang_aimin2000\「开始」菜单\程序\启动\cmd.lnk --> C:\WINDOWS\Temp\serlass.exe [N/A]><N>
[RegVac]
  <C:\Documents and Settings\yang_aimin2000\「开始」菜单\程序\启动\RegVac.lnk --> C:\PROGRA~1\RegVac\regvac.exe [N/
这些启动项删除

C:\WINDOWS\Temp\serlass.exe这个按路径删除

你的报告怎么这样的,看的我眼都花了
wangjay1980
发表于 2007-4-7 13:15:53 | 显示全部楼层
另外装个防火墙
我不告诉你
 楼主| 发表于 2007-4-7 23:14:52 | 显示全部楼层
再一次感谢你的帮助。我装的是za墙汉化版
neu21
发表于 2007-4-8 00:38:47 | 显示全部楼层
直接360safe就行了何必这么麻烦呢
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 03:05 , Processed in 0.137387 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表