楼主: jojo108
收起左侧

[已解决] 求助 这个木马无法清除啊

[复制链接]
jojo108
 楼主| 发表于 2007-5-1 10:54:01 | 显示全部楼层
正在用你们给我的软件查
jojo108
 楼主| 发表于 2007-5-1 11:03:06 | 显示全部楼层
SREng.EXE 我下的应该是最新版本吧  但是打开需要授权号
jojo108
 楼主| 发表于 2007-5-1 11:03:48 | 显示全部楼层
用windows清理助手查杀了几个木马,已经清除了 但是还是有我刚才那个毛病
jojo108
 楼主| 发表于 2007-5-1 11:07:51 | 显示全部楼层
用SRE扫描的报告有了:

  1. 2001-05-01,11:05:12
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件

  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17.     <STYLEXP><C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide>  []
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.     <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  20.     <!AVG Anti-Spyware><"E:\AVG\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [Anti-Malware Development a.s.]
  21.     <Kvsc3><C:\WINDOWS\Kvsc3.exe>  []
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  23.     <MSDEG32    ><LYLoader.exe>  [N/A]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  25.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  26.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
  27.     <UIHost><C:\Program Files\TGTSoft\StyleXP\Logon\CurrentLogon.EXE>  []
  28. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  29.     <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><E:\AVG\AVG Anti-Spyware 7.5\shellexecutehook.dll>  [Anti-Malware Development a.s.]
  30.     <{42A612A4-4334-4424-4234-42261A31A236}><C:\WINDOWS\system32\pdkpri.dll>  []
  31. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  32.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
  33. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  34.     <BigDog303><; C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)>  [N/A]
  35.     <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  36.     <miniqqlive><; >  [N/A]
  37.     <PHIME2002A><; >  [N/A]
  38.     <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  39.     <StormCodec_Helper><; "E:\Storm Codec\StormSet.exe" /S /opti>  [N/A]
  40.     <Windows木马防火墙><; >  [N/A]
  41. ==================================
  42. 启动文件夹
  43. N/A
  44. ==================================
  45. 服务
  46. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  47.   <E:\AVG\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
  48. [卡巴斯基反病毒6.0 / AVP][Stopped/Auto Start]
  49.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  50. [Human Interface Device Access / HidServ][Stopped/Auto Start]
  51.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  52. [StyleXPService / StyleXPService][Stopped/Auto Start]
  53.   <"C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"><>
  54. [WinWMServiceNow / WinWMServiceNow][Stopped/Auto Start]
  55.   <C:\DOCUME~1\jojo\LOCALS~1\Temp\RAVWM.EXE><N/A>
  56. ==================================
  57. 驱动程序
  58. [00007384 / 00007384][Stopped/Boot Start]
  59.   <\SystemRoot\system32\drivers\00007384.SYS><N/A>
  60. [338703 / 338703][Running/]
  61.   <2 - 系统找不到指定的文件。
  62. ><N/A>
  63. [a0 / a0][Running/]
  64.   <2 - 系统找不到指定的文件。
  65. ><N/A>
  66. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  67.   <system32\drivers\ac97intc.sys><Intel Corporation>
  68. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  69.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  70. [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  71.   <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
  72. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  73.   <\??\E:\AVG\AVG Anti-Spyware 7.5\guard.sys><N/A>
  74. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  75.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  76. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  77.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  78. [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  79.   <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
  80. [kl1 / kl1][Running/Boot Start]
  81.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  82. [klif / klif][Running/System Start]
  83.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  84. [Netgroup Packet Filter / NPF][Stopped/Manual Start]
  85.   <system32\DRIVERS\npf.sys><CACE Technologies>
  86. [npkcrypt / npkcrypt][Running/Auto Start]
  87.   <\??\C:\Program Files\QQ2006\npkcrypt.sys><INCA Internet Co., Ltd.>
  88. [nv / nv][Stopped/Manual Start]
  89.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  90. [Pnpnt / Pnpnt][Stopped/Boot Start]
  91.   <\SystemRoot\System32\Drivers\pnpnt.sys><N/A>
  92. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  93.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  94. [Secdrv / Secdrv][Stopped/Manual Start]
  95.   <system32\DRIVERS\secdrv.sys><N/A>
  96. [StyleXPHelper / StyleXPHelper][Running/System Start]
  97.   <\??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe><Windows (R) 2000 DDK provider>
  98. [SVKP / SVKP][Running/Auto Start]
  99.   <\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
  100. [TrojanFindDriverNT / TrojanFindDriverNT][Stopped/Manual Start]
  101.   <\??\C:\WINDOWS\system32\NtDriver.sys><N/A>
  102. [viagfx / viagfx][Running/Manual Start]
  103.   <system32\DRIVERS\vtmini.sys><Copyright (C) VIA/S3 Graphics Co, Ltd.>
  104. [ViaIde / ViaIde][Running/Boot Start]
  105.   <\SystemRoot\system32\DRIVERS\viaidexp.sys><VIA Technologies, Inc.>
  106. [VIAMRAID / VIAMRAID][Stopped/Boot Start]
  107.   <\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
  108. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  109.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  110. [VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Running/Manual Start]
  111.   <System32\Drivers\usbVM303.sys><Vimicro Corporation>
  112. ==================================
  113. 浏览器加载项
  114. [启动迅雷]
  115.   {0062C9BD-B349-40DE-91A0-755F37ACD559} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
  116. [Web反病毒保护]
  117.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  118. [信息检索(&R)]
  119.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  120. [Shockwave Flash Object]
  121.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  122. [AxisMediaControlEmb Class]
  123.   {DE625294-70E6-45ED-B895-CFFA13AEB044} <C:\Program Files\Axis Communications\AXIS Media Control Embedded\AxisMediaControlEmb.dll, Axis Communications>
  124. []
  125.   {105E4D0C-5E21-41ED-90F9-013EEF271BD6} <C:\WINDOWS\system32\widgetdownload.dll, 鱼鱼桌面秀widget插件下载工具>
  126. [HTML Document]
  127.   {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
  128. [Shell Name Space]
  129.   {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
  130. [Windows Media Player]
  131.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  132. [Active Desktop Mover]
  133.   {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
  134. [Thunder Browser Helper]
  135.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
  136. [SearchAssistantOC]
  137.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  138. [Shockwave Flash Object]
  139.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  140. [&使用BitComet下载]
  141.   <res://E:\BitComet\BitComet.exe/AddLink.htm, N/A>
  142. [&使用BitComet下载全部链接]
  143.   <res://E:\BitComet\BitComet.exe/AddAllLink.htm, N/A>
  144. [&使用BitComet下载本页视频]
  145.   <res://E:\BitComet\BitComet.exe/AddVideo.htm, N/A>
  146. [&使用迅雷下载]
  147.   <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
  148. [&使用迅雷下载全部链接]
  149.   <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
  150. [导出到 Microsoft Office Excel(&X)]
  151.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  152. [用维棠下载视频]
  153.   <E:\维棠FLV\vd_link.htm, N/A>
  154. ==================================
  155. 正在运行的进程
  156. [PID: 616][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  157. [PID: 680][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  158. [PID: 704][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  159.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  160.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  161. [PID: 748][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  162. [PID: 760][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  163. [PID: 920][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  164. [PID: 984][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  165. [PID: 1016][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  166. [PID: 204][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  167.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  168.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  169.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  170. [PID: 192][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  171.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  172.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  173.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  174.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  175.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  176.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  177. [PID: 140][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  178.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  179.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  180.     [E:\AVG\AVG Anti-Spyware 7.5\shellexecutehook.dll]  [Anti-Malware Development a.s., 7, 5, 0, 47]
  181.     [C:\WINDOWS\system32\pdkpri.dll]  [N/A, ]
  182.     [C:\WINDOWS\system32\WINABCX.IME]  [PKUETI, 5.22.216]
  183.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  184.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
  185.     [E:\AVG\AVG Anti-Spyware 7.5\context.dll]  [Anti-Malware Development a.s., 7, 5, 0, 49]
  186. [PID: 2796][E:\myIE2\m2zipcn\MyIE.exe]  [MY Soft Technology, 0, 9, 27, 68]
  187.     [E:\myIE2\m2zipcn\Plugin\uc\uc.dll]  [, 1, 0, 0, 1]
  188.     [E:\myIE2\m2zipcn\Plugin\ViewSource\ViewSrc.dll]  [, 1, 0, 0, 1]
  189.     [E:\myIE2\m2zipcn\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
  190.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  191.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  192.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  193.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  194.     [C:\WINDOWS\system32\WINABCX.IME]  [PKUETI, 5.22.216]
  195.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  196. [PID: 3084][E:\2222\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  197. ==================================
  198. 文件关联
  199. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  200. .EXE  OK. ["%1" %*]
  201. .COM  OK. ["%1" %*]
  202. .PIF  OK. ["%1" %*]
  203. .REG  OK. [regedit.exe "%1"]
  204. .BAT  OK. ["%1" %*]
  205. .SCR  OK. ["%1" /S]
  206. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  207. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  208. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  209. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  210. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  211. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  212. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  213. ==================================
  214. Winsock 提供者
  215. N/A
  216. ==================================
  217. Autorun.inf
  218. N/A
  219. ==================================
  220. HOSTS 文件
  221. 127.0.0.1  localhost
  222. ==================================
  223. API HOOK
  224. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5AA5B25)
  225. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5AA5D67)
  226. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5AA5F0B)
  227. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5AA5C49)
  228. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF5AA5E8F)
  229. ==================================
  230. 隐藏进程
  231. N/A
  232. ==================================
复制代码
jojo108
 楼主| 发表于 2007-5-1 11:10:59 | 显示全部楼层
还有这个不知道该怎么办?
11.JPG
jojo108
 楼主| 发表于 2007-5-1 11:12:02 | 显示全部楼层
2位都不在了吗?
jojo108
 楼主| 发表于 2007-5-1 11:13:23 | 显示全部楼层
SRE这个可以修复吗?
22.JPG
xffsfy
发表于 2007-5-1 12:25:29 | 显示全部楼层
试试其他的流氓清理软件啊~~~
帮你顶上去先~~~王版主爱看这个
jojo108
 楼主| 发表于 2007-5-1 13:41:24 | 显示全部楼层
原帖由 xffsfy 于 2007-5-1 12:25 发表
试试其他的流氓清理软件啊~~~
帮你顶上去先~~~王版主爱看这个



谢谢 呵呵~  在360+冰刃+卡巴+AVG+Windows清理助手+SRE的集体努力下,现在终于把病毒和木马们都删除干净了,最后那个难杀的还是360搞定的(貌似也是卡巴)   

现在终于好了,谢谢以上帮我的各位,3Q~

以后再也不上网看小说了    整整弄了一上午 啥也没干 光重起电脑了
marliy
发表于 2007-5-1 14:20:32 | 显示全部楼层
上一些大型的安全网去看小说吧··
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 07:48 , Processed in 0.123714 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表