楼主: 无名浪者
收起左侧

Trojan-Spy.win32.Agent.pn杀完还有(附上扫描报告)

[复制链接]
无名浪者
 楼主| 发表于 2007-5-20 15:35:34 | 显示全部楼层
原帖由 pizai0 于 2007-5-20 12:53 发表
这是本站会员shuihuorouqing
提供的解决办法...很实用....我已杀掉
下载一个叫unlocker的软件,很小的,用搜索引擎一找就能找到的,然后安装在任意目录。
C:\WINDOWS\system32 下找到病毒文件(文件应该是一 ...




我刚刚看了你说的那个人的方法,他是杀这个病毒的:Trojan-Downloader.Win32.QQHelper.mo的方法,跟我中的病毒不一样把
无名浪者
 楼主| 发表于 2007-5-20 15:40:27 | 显示全部楼层
原帖由 wangjay1980 于 2007-5-20 14:37 发表
用这个和360进行一下清理,然后卸载QQ,最后再用卡巴查杀一遍




arswp整个用过,但是我用它来扫描并查杀垃圾软件的时候,跟着每次打开电脑就会出现XXXX加载错误,找不到模块之类的话,360倒没试过。

[ 本帖最后由 无名浪者 于 2007-5-20 15:45 编辑 ]
无名浪者
 楼主| 发表于 2007-5-20 16:11:43 | 显示全部楼层
这是wangjay1980版主一个半月前给一个中了和我一样病毒的会员的解答方法,但是我看不明白,你能不能说明一下呢

<Userinit><userinit.exe,rundll32.exe start,rundll32.exe start>  这个修改为<Userinit><C:\WINDOWS\system32\userinit.exe,>

<{08315C1A-9BA9-4B7C-A432-26885F78DF28}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.vxd>  [N/A]
<DAEMON Tools-2052><; >  [N/A]
这两个启动项删除

[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\D:\Tools\setup here\QQ\npkycryp.sys><N/A>
这个驱动删除
C:\Program Files\Common Files\Microsoft Shared\MSINFO\xiaran.vxd
按路径删除




究竟具体怎么删除
wangjay1980
发表于 2007-5-20 17:27:28 | 显示全部楼层
你先把QQ删除了,然后安全模式下用卡巴杀毒,最好用这个在扫个报告看看

sreng2.zip

597.63 KB, 下载次数: 13

无名浪者
 楼主| 发表于 2007-5-20 23:09:53 | 显示全部楼层
原帖由 wangjay1980 于 2007-5-20 17:27 发表
你先把QQ删除了,然后安全模式下用卡巴杀毒,最好用这个在扫个报告看看




是卸载还是退出QQ?
wangjay1980
发表于 2007-5-20 23:10:41 | 显示全部楼层
卸载
无名浪者
 楼主| 发表于 2007-5-21 11:02:01 | 显示全部楼层
按照版主的方法,卸载QQ,在安全模式下咔吧杀毒,这次杀出的是另一个病毒:
Trojan-Downloader.BAT.Ftp.ab   ,问一下版主,这个木马怎么杀????????


下面是扫描报告


  1. 2007-05-21,10:53:30

  2. System Repair Engineer 2.3.13.690
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 1 (Build 2600)
  5. - 管理权限用户 - 完整功能

  6. 以下内容被选中:
  7.     所有的启动项目(包括注册表、启动文件夹、服务等)
  8.     浏览器加载项
  9.     正在运行的进程(包括进程模块信息)
  10.     文件关联
  11.     Winsock 提供者
  12.     Autorun.inf
  13.     HOSTS 文件


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
  18.     <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit>  [(Verified)NVIDIA Corporation]
  19. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  20.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
  21.     <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
  22.     <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
  23.     <SoundMan><SOUNDMAN.EXE>  [(Verified)Realtek Semiconductor Corp.]
  24.     <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [(Verified)NVIDIA Corporation]
  25.     <nwiz><nwiz.exe /install>  [NVIDIA Corporation]
  26.     <AVP><"E:\Program Files\Kaspersky\avp.exe">  [Kaspersky Lab]
  27.     <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.     <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
  30.     <Userinit><c:\windows\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
  31. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  32.     <AppInit_DLLs><>  [N/A]
  33. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  34.     <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  36.     <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Corporation]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  38.     <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Corporation]
  39.     <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Corporation]
  40.     <WebCheck><%SystemRoot%\System32\webcheck.dll>  [(Verified)Microsoft Corporation]
  41.     <SysTray><C:\WINDOWS\System32\stobject.dll>  [(Verified)Microsoft Corporation]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
  43.     <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Corporation]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
  45.     <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Corporation]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
  47.     <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Corporation]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  49.     <WinlogonNotify: klogon><C:\WINDOWS\System32\klogon.dll>  [Kaspersky Lab]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
  51.     <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Corporation]
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
  53.     <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Corporation]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
  55.     <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Corporation]
  56. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
  57.     <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Corporation]
  58. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
  59.     <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Corporation]
  60. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
  61.     <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Corporation]
  62. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
  63.     <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Corporation]
  64.     <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Corporation]

  65. ==================================
  66. 启动文件夹
  67. N/A

  68. ==================================
  69. 服务
  70. [卡巴斯基互联网安全套装6.0 / AVP][Stopped/Auto Start]
  71.   <E:\Program Files\Kaspersky\avp.exe -r><Kaspersky Lab>
  72. [Human Interface Device Access / HidServ][Stopped/Disabled]
  73.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  74. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  75.   <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
  76. [Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  77.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>

  78. ==================================
  79. 驱动程序
  80. [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  81.   <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
  82. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  83.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  84. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  85.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  86. [basic2 / basic2][Stopped/Manual Start]
  87.   <System32\DRIVERS\HSF_BSC2.sys><Conexant>
  88. [Creative SBLive! Gameport / ctljystk][Stopped/Manual Start]
  89.   <System32\DRIVERS\ctljystk.sys><Creative Technology Ltd.>
  90. [Creative SB Live! (WDM) / emu10k][Stopped/Manual Start]
  91.   <system32\drivers\emu10k1m.sys><Creative Technology Ltd.>
  92. [Creative Interface Manager Driver (WDM) / emu10k1][Stopped/Manual Start]
  93.   <system32\drivers\ctlfacem.sys><Creative Technology Ltd.>
  94. [HSFHWBS2 / HSFHWBS2][Running/Manual Start]
  95.   <System32\DRIVERS\HSFHWBS2.sys><Conexant Systems>
  96. [HSF_DP / HSF_DP][Running/Manual Start]
  97.   <System32\DRIVERS\HSF_DP.sys><Conexant Systems>
  98. [hsf_msft / hsf_msft][Stopped/Manual Start]
  99.   <System32\DRIVERS\HSF_MSFT.sys><Conexant>
  100. [kl1 / kl1][Running/Boot Start]
  101.   <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
  102. [klif / klif][Running/System Start]
  103.   <\??\C:\WINDOWS\System32\drivers\klif.sys><Kaspersky Lab>
  104. [mdmxsdk / mdmxsdk][Running/Auto Start]
  105.   <System32\DRIVERS\mdmxsdk.sys><Conexant>
  106. [nv / nv][Running/Manual Start]
  107.   <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  108. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  109.   <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  110. [Rksample / Rksample][Stopped/Manual Start]
  111.   <System32\DRIVERS\HSF_SAMP.sys><Conexant>
  112. [Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
  113.   <System32\DRIVERS\R8139n51.SYS><Realtek Semiconductor Corporation>
  114. [Secdrv / Secdrv][Stopped/Manual Start]
  115.   <System32\DRIVERS\secdrv.sys><N/A>
  116. [Creative SoundFont Manager Driver (WDM) / sfman][Stopped/Manual Start]
  117.   <system32\drivers\sfmanm.sys><Creative Technology Ltd.>
  118. [SiS AGP Filter / SISAGP][Running/Boot Start]
  119.   <\SystemRoot\System32\DRIVERS\SISAGPX.sys><Silicon Integrated Systems Corporation>
  120. [SiSide / SiSide][Running/Boot Start]
  121.   <\SystemRoot\System32\DRIVERS\siside.sys><Silicon Integrated Systems Corp.>
  122. [TSP / TSP][Stopped/Manual Start]
  123.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  124. [Conexant Setup API / UIUSys][Stopped/Manual Start]
  125.   <system32\drivers\UIUSys.sys><Conexant>
  126. [winachsf / winachsf][Running/Manual Start]
  127.   <System32\DRIVERS\HSF_CNXT.sys><Conexant Systems>
  128. [PCANDIS5 NDIS Protocol Driver / PCANDIS5][Running/Manual Start]
  129.   <\??\C:\WINDOWS\System32\PCANDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>

  130. ==================================
  131. 浏览器加载项
  132. [FGCatchUrl]
  133.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <E:\Program Files\FlashGet\jccatch.dll, [url]www.flashget.com[/url]>
  134. [Web反病毒保护 统计]
  135.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <E:\Program Files\Kaspersky\scieplugin.dll, Kaspersky Lab>
  136. [@shdoclc.dll,-866]
  137.   {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
  138. [快车]
  139.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <E:\PROGRA~1\FLASHGET\flashget.exe, FlashGet.com>
  140. [电台(&R)]
  141.   {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
  142. [快车(FlashGet)]
  143.   {E0E899AB-F487-11D5-8D29-0050BA6940E3} <E:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
  144. [FGCatchUrl]
  145.   {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <E:\Program Files\FlashGet\jccatch.dll, [url]www.flashget.com[/url]>
  146. [&使用网际快车下载]
  147.   <E:\Program Files\FlashGet\jc_link.htm, N/A>
  148. [&使用网际快车下载全部链接]
  149.   <E:\Program Files\FlashGet\jc_all.htm, N/A>
  150. [上传到QQ网络硬盘]
  151.   <E:\Program Files\qq\AddToNetDisk.htm, N/A>
  152. [添加到QQ自定义面板]
  153.   <E:\Program Files\qq\AddPanel.htm, N/A>
  154. [添加到QQ表情]
  155.   <E:\Program Files\qq\AddEmotion.htm, N/A>
  156. [用QQ彩信发送该图片]
  157.   <E:\Program Files\qq\SendMMS.htm, N/A>

  158. ==================================
  159. 正在运行的进程
  160. [PID: 476][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  161. [PID: 552][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  162. [PID: 576][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  163.     [C:\WINDOWS\System32\klogon.dll]  [Kaspersky Lab, 6.0.2.621]
  164. [PID: 620][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  165. [PID: 632][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  166. [PID: 804][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  167. [PID: 856][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  168.     [E:\Program Files\Kaspersky\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]
  169. [PID: 940][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  170. [PID: 976][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  171. [PID: 1244][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
  172.     [E:\Program Files\Kaspersky\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
  173.     [C:\WINDOWS\System32\nvshell.dll]  [NVIDIA Corporation, 6.14.10.5303]
  174.     [C:\WINDOWS\System32\NVWRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.5303]
  175. [PID: 1308][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
  176. [PID: 1836][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.14]
  177. [PID: 1924][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3427]
  178. [PID: 1940][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  179. [PID: 1956][C:\WINDOWS\System32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  180.     [C:\WINDOWS\System32\NVMCTRAY.DLL]  [NVIDIA Corporation, 6.14.10.5303]
  181.     [C:\WINDOWS\System32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.5303]
  182. [PID: 2028][C:\WINDOWS\System32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.5303]
  183. [PID: 1432][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  184. [PID: 1680][E:\软件\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
  185.     [E:\Program Files\Kaspersky\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]

  186. ==================================
  187. 文件关联
  188. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  189. .EXE  OK. ["%1" %*]
  190. .COM  OK. ["%1" %*]
  191. .PIF  OK. ["%1" %*]
  192. .REG  OK. [regedit.exe "%1"]
  193. .BAT  OK. ["%1" %*]
  194. .SCR  OK. ["%1" /S]
  195. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  196. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  197. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  198. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  199. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  200. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  201. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  202. ==================================
  203. Winsock 提供者
  204. N/A

  205. ==================================
  206. Autorun.inf
  207. N/A

  208. ==================================
  209. HOSTS 文件
  210. 127.0.0.1       localhost

  211. ==================================
  212. API HOOK
  213. 警告!System Repair Engineer 提醒
  214. 你下面的函数内容与预期值不符,他
  215. 们可能被一些恶意的软件所修改:
  216. RVA  错误: LoadLibraryA
  217. RVA  错误: LoadLibraryExA
  218. RVA  错误: LoadLibraryExW
  219. RVA  错误: LoadLibraryW

  220. ==================================


复制代码
无名浪者
 楼主| 发表于 2007-5-21 11:20:42 | 显示全部楼层
关于Trojan-Downloader.BAT.Ftp.ab的病毒本论坛已经有人提问过,但是还没有什么有效的方法来彻底杀掉这个病毒。以下是那个帖子的连接
http://bbs.kafan.cn/viewthread.p ... T.Ftp.ab&page=1
无名浪者
 楼主| 发表于 2007-5-21 16:15:51 | 显示全部楼层
我刚查了一下,是木马下载病毒,现在还没有有效的彻底杀毒方法
wangjay1980
发表于 2007-5-21 19:55:46 | 显示全部楼层
你的系统密码是不是没有
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 12:36 , Processed in 0.090259 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表