楼主: zcphome
收起左侧

[已解决] 我崩溃,有这么牛B的木马.病毒啊

[复制链接]
zcphome
 楼主| 发表于 2007-6-7 19:50:26 | 显示全部楼层
估计所有关于杀毒方面的。exe文件都打不开
zcphome
 楼主| 发表于 2007-6-7 20:02:03 | 显示全部楼层
我中的是木马啊
因为发现插上U盘以后
换另一台电脑显示AUTO
wangjay1980
发表于 2007-6-7 20:04:07 | 显示全部楼层
先一键恢复,然后下载冰刃放到桌面上,用冰刃查看各盘的文件,如果发现AUTORUN和可疑的文件,就删除。删除后再用杀软杀毒

记住操作过程中不要打开非系统盘
zcphome
 楼主| 发表于 2007-6-7 20:19:15 | 显示全部楼层
楼上的 我就是这么弄的
这是扫描 后的内容

  1. 2007-06-07,20:15:35
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件

  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  18.     <load><>  [N/A]
  19. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  20.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  21.     <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
  22.     <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
  23.     <IgfxTray><C:\WINDOWS\system32\igfxtray.exe>  [(Verified)Microsoft Windows Publisher]
  24.     <HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  25.     <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Publisher]
  26.     <AGRSMMSG><AGRSMMSG.exe>  [(Verified)Microsoft Windows Publisher]
  27.     <NovoKey><C:\Program Files\NovoKey\NovoKey.exe>  []
  28.     <Apoint><C:\Program Files\Apoint2K\Apoint.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  29.     <ZCfgSvc.exe><C:\WINDOWS\system32\ZCfgSvc.exe>  [Intel Corporation]
  30.     <PRONoMgr.exe><C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe>  [Intel(R) Corporation]
  31. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  32.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  33.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  34. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  35.     <AppInit_DLLs><>  [N/A]
  36. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  37.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]
  39.     <WinlogonNotify: Sebring><C:\WINDOWS\system32\LgNotify.dll>  [Intel Corporation]
  40. ==================================
  41. 启动文件夹
  42. N/A
  43. ==================================
  44. 服务
  45. [Application Management / AppMgmt][Stopped/Manual Start]
  46.   <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
  47. [RegSrvc / RegSrvc][Running/Auto Start]
  48.   <C:\WINDOWS\system32\RegSrvc.exe><Intel Corporation>
  49. [Spectrum24 Event Monitor / S24EventMonitor][Running/Auto Start]
  50.   <C:\WINDOWS\system32\S24EvMon.exe><Intel Corporation>
  51. ==================================
  52. 驱动程序
  53. [AEGIS Protocol (IEEE 802.1x) v3.0.0.5 / AegisP][Running/Auto Start]
  54.   <system32\DRIVERS\AegisP.sys><Meetinghouse Data Communications>
  55. [Agere Systems Soft Modem / AgereSoftModem][Running/Manual Start]
  56.   <system32\DRIVERS\AGRSM.sys><Agere Systems>
  57. [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  58.   <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
  59. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  60.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  61. [Alps Pointing-device Filter Driver / ApfiltrService][Running/Manual Start]
  62.   <system32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
  63. [Atheros Wireless Network Adapter Service / AR5211][Stopped/Manual Start]
  64.   <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
  65. [ialm / ialm][Running/Manual Start]
  66.   <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
  67. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  68.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  69. [Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  70.   <system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
  71. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  72.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  73. [WLAN Transport / s24trans][Running/Auto Start]
  74.   <system32\DRIVERS\s24trans.sys><Intel Corporation>
  75. [Secdrv / Secdrv][Stopped/Manual Start]
  76.   <system32\DRIVERS\secdrv.sys><N/A>
  77. [适用于 Windows XP 的英特尔(R) PRO/无线 2200 适配器驱动程序 / w22n51][Stopped/Manual Start]
  78.   <system32\DRIVERS\w22n51.sys><Intel? Corporation>
  79. [Intel(R) PRO/Wireless 7100 Adapter 驱动程序 / w70n51][Stopped/Manual Start]
  80.   <system32\DRIVERS\w70n51.sys><Intel? Corporation>
  81. ==================================
  82. 浏览器加载项
  83. [联想]
  84.   {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
  85. [Messenger]
  86.   {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
  87. ==================================
  88. 正在运行的进程
  89. [PID: 356][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  90. [PID: 428][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  91. [PID: 452][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  92.     [C:\WINDOWS\system32\LgNotify.dll]  [Intel Corporation, 8, 1, 0, 44]
  93.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  94. [PID: 496][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  95. [PID: 1724][C:\WINDOWS\system32\ZCfgSvc.exe]  [Intel Corporation, 8, 1, 0, 44]
  96.     [C:\WINDOWS\system32\PfMgrApi.dll]  [Intel Corporation, 8, 1, 0, 44]
  97.     [C:\WINDOWS\system32\PsRegApi.dll]  [Intel Corporation, 8, 1, 0, 44]
  98.     [C:\WINDOWS\system32\WConfig.DLL]  [Intel Corporation, 8, 1, 0, 44]
  99.     [C:\WINDOWS\system32\WiFiAdap.DLL]  [Intel Corporation, 8, 1, 0, 44]
  100.     [C:\WINDOWS\system32\PsGuiMgr.dll]  [Intel Corporation., 8, 1, 0, 44]
  101.     [C:\WINDOWS\system32\ShellNav.dll]  [, 1, 0, 0, 1]
  102.     [C:\WINDOWS\system32\C1XStngs.dll]  [Intel Corporation, 8, 1, 0, 44]
  103.     [C:\WINDOWS\system32\LSAWRAPI.dll]  [N/A, ]
  104.     [C:\Program Files\Intel\PROSetWireless\PROSet\CHS\ZcSvcCHS.dll]  [Intel Corporation, 8, 1, 0, 44]
  105.     [C:\WINDOWS\system32\S24MUDLL.dll]  [Intel Corporation, 8, 1, 0, 44]
  106.     [C:\WINDOWS\system32\D8021Xps.dll]  [N/A, ]
  107.     [C:\Program Files\Intel\PROSetWireless\PROSet\CHS\C1XStCHS.dll]  [Intel Corporation, 8, 1, 0, 44]
  108.     [C:\Program Files\Intel\PROSetWireless\PROSet\CHS\PmApiCHS.dll]  [Intel Corporation, 8, 1, 0, 44]
  109. [PID: 628][C:\WINDOWS\system32\1XConfig.exe]  [Intel, 8, 1, 0, 44]
  110.     [C:\WINDOWS\system32\IntelAE5.dll]  [Meetinghouse Data Communications, 5, 0, 3, 1]
  111.     [C:\WINDOWS\system32\PsRegApi.dll]  [Intel Corporation, 8, 1, 0, 44]
  112.     [C:\WINDOWS\system32\D8021Xps.dll]  [N/A, ]
  113. [PID: 1720][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  114.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  115. [PID: 1172][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  116. [PID: 1472][C:\WINDOWS\system32\igfxtray.exe]  [Intel Corporation, 3.0.0.3792]
  117.     [C:\WINDOWS\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.3792]
  118.     [C:\WINDOWS\system32\igfxdev.dll]  [Intel Corporation, 3.0.0.3792]
  119.     [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3792]
  120.     [C:\WINDOWS\system32\igfxres.dll]  [Intel Corporation, 3.0.0.3792]
  121.     [C:\WINDOWS\system32\igfxress.dll]  [Intel Corporation, 3.0.0.3792]
  122. [PID: 1476][C:\WINDOWS\system32\hkcmd.exe]  [Intel Corporation, 3.0.0.3792]
  123.     [C:\WINDOWS\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.3792]
  124.     [C:\WINDOWS\system32\igfxdev.dll]  [Intel Corporation, 3.0.0.3792]
  125.     [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.3792]
  126.     [C:\WINDOWS\system32\igfxres.dll]  [Intel Corporation, 3.0.0.3792]
  127.     [C:\WINDOWS\system32\igfxhk.dll]  [Intel Corporation, 3.0.0.3792]
  128. [PID: 1460][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.24]
  129. [PID: 1468][C:\WINDOWS\AGRSMMSG.exe]  [Agere Systems, 2.1.23 2.1.23 01/22/2003 17:47:39]
  130. [PID: 1688][C:\Program Files\NovoKey\NovoKey.exe]  [, 1, 0, 0, 0]
  131. [PID: 1760][C:\Program Files\Apoint2K\Apoint.exe]  [Alps Electric Co., Ltd., 5.5.1.185]
  132.     [C:\WINDOWS\system32\VXDIF.DLL]  [Alps Electric Co., Ltd., 6.0.2.69]
  133.     [C:\Program Files\Apoint2K\Apoint.DLL]  [Alps Electric Co., Ltd., 5.5.1.257]
  134.     [C:\Program Files\Apoint2K\EzAuto.dll]  [Alps Electric Co., Ltd., 5.5.1.85]
  135.     [C:\Program Files\Apoint2K\EzLaunch.DLL]  [Alps Electric Co., Ltd., 5.5.1.61]
  136. [PID: 1904][C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe]  [Intel(R) Corporation, 6.1.304.0]
  137.     [C:\Program Files\Intel\PROSetWireless\NCS\PROSet\CHSPGUIR.dll]  [Intel(R) Corporation, 6.1.304.0]
  138.     [C:\WINDOWS\system32\Pn802_11.dll]  [Intel Corporation., 1, 0, 0, 0]
  139.     [C:\WINDOWS\system32\PfMgrApi.dll]  [Intel Corporation, 8, 1, 0, 44]
  140.     [C:\WINDOWS\system32\PsRegApi.dll]  [Intel Corporation, 8, 1, 0, 44]
  141.     [C:\WINDOWS\system32\WConfig.DLL]  [Intel Corporation, 8, 1, 0, 44]
  142.     [C:\WINDOWS\system32\WiFiAdap.DLL]  [Intel Corporation, 8, 1, 0, 44]
  143.     [C:\WINDOWS\system32\C1XStngs.dll]  [Intel Corporation, 8, 1, 0, 44]
  144.     [C:\WINDOWS\system32\ShellNav.dll]  [, 1, 0, 0, 1]
  145.     [C:\WINDOWS\system32\LSAWRAPI.dll]  [N/A, ]
  146.     [C:\Program Files\Intel\PROSetWireless\PROSet\CHS\PNC11CHS.dll]  [Intel Corporation., 1, 0, 0, 0]
  147.     [C:\WINDOWS\system32\S24MUDLL.dll]  [Intel Corporation, 8, 1, 0, 44]
  148.     [C:\WINDOWS\system32\D8021Xps.dll]  [N/A, ]
  149.     [C:\Program Files\Intel\PROSetWireless\PROSet\CHS\PmApiCHS.dll]  [Intel Corporation, 8, 1, 0, 44]
  150. [PID: 2052][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  151. [PID: 2096][C:\Program Files\Apoint2K\Apntex.exe]  [Alps Electric Co., Ltd., 5.5.1.16]
  152.     [C:\WINDOWS\system32\VXDIF.DLL]  [Alps Electric Co., Ltd., 6.0.2.69]
  153. [PID: 2120][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  154. [PID: 2488][F:\sreng\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  155. ==================================
  156. 文件关联
  157. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  158. .EXE  OK. ["%1" %*]
  159. .COM  OK. ["%1" %*]
  160. .PIF  OK. ["%1" %*]
  161. .REG  OK. [regedit.exe "%1"]
  162. .BAT  OK. ["%1" %*]
  163. .SCR  OK. ["%1" /S]
  164. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  165. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  166. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  167. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  168. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  169. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  170. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  171. ==================================
  172. Winsock 提供者
  173. N/A
  174. ==================================
  175. Autorun.inf
  176. [D:\]
  177. [AutoRun]
  178. open=8EC94FF6.exe
  179. shell\open=打开(&O)
  180. shell\open\Command=8EC94FF6.exe
  181. shell\open\Default=1
  182. shell\explore=资源管理器(&X)
  183. shell\explore\Command=8EC94FF6.exe
  184. ==================================
  185. HOSTS 文件
  186. 127.0.0.1       localhost
  187. ==================================
  188. API HOOK
  189. N/A
  190. ==================================
  191. 隐藏进程
  192. N/A
  193. ==================================
复制代码
ooo-ppp
发表于 2007-6-7 20:21:20 | 显示全部楼层
先看看这个http://bbs.kafan.cn/viewthread.php?tid=79940&extra=page%3D2
       如嫌麻烦就简化些,使用狙剑在启动项中找到病毒相关内容(通过所属公司,文件创建时间,文件属性等甄别),然后锁定系统,删除启动项,重启计算机,再删除文件.
       如不能启动.可将扩展名改为.com后执行即可.病毒程序利用Debuger关联,使得当前大多数的杀毒软件与安全软件在启动时都会调用木马程序以调试状态启动。而狙剑的自启动项检查,在此之前是不检查此项的,当然了,新版已经加入了。
      嫌不直观就到http://free.ys168.com/?wangsea下载wsyscheck(0602)中文版,利用安全检查下-常规检查中禁用程序管理中,用右键单击选中文件-允许这个文件运行,即可解除映像劫持,执行工具软件.
      还可以用汉化版autoruns,钩选选项中校验数字签名&隐藏有微软签名的项目后,删除映像劫持下内容.
zcphome
 楼主| 发表于 2007-6-7 20:27:41 | 显示全部楼层
冰刃  不知道那个是要删除的啊
zcphome
 楼主| 发表于 2007-6-7 20:31:46 | 显示全部楼层
15楼的 看不懂啊
zcphome
 楼主| 发表于 2007-6-7 20:34:31 | 显示全部楼层
用冰刃没有看到红色标识的
zcphome
 楼主| 发表于 2007-6-7 20:47:28 | 显示全部楼层
我只有2个盘

c

c

d

d
wangjay1980
发表于 2007-6-7 20:49:02 | 显示全部楼层
用冰刃查D盘
删除这个Autorun.inf
[D:\]
[AutoRun]
open=8EC94FF6.exe
shell\open=打开(&O)
shell\open\Command=8EC94FF6.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=8EC94FF6.exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-4 05:06 , Processed in 0.099230 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表