12345   4  /  5  页   跳转

如何杀Trojan.DL.Agent.dtp病毒.

引用:
【沿边的贴子】我只找着C:\WINDOWS\System32\mstasks. dll;没有找到有C:\WINDOWS\htpatch.exe,找了好几遍,也还是没有

...........................

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-12-7 17:01:31
描述:



gototop
 

我解决此毒了,呵呵,在安全模式下杀.
gototop
 

是啊,我是在选择显示所有文件的情况下找的,刚刚我又找了一遍,还是没有,和刚才我说的 情况一样
gototop
 

找着那个htpatch了,图标象是条码,是那个吗
mstask的后缀还是dll,不是exe
gototop
 

再扫描一个Autoruns日志

font_color=#0000FF]保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ BigDog303VimicroVimicroc:\windows\vm303_sti.exe

+ ExFiltercdnspiec:\program files\cnnic\cdn\cdnspie.dll

+ LenSoftFlyShuttle Microsoft 基础类应用程序c:\program files\lenovo\幸福一键通\flyshuttle.exe

+ Lskbdrvc:\program files\lenovo\幸福一键通\kbdriver.exe

+ NvCplDaemonNVIDIA Taskbar Utility LibraryNVIDIA Corporationc:\windows\system32\nvqtwk.dll

+ nwizNVIDIA nView Control Panel, Version 28.32 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe

+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.C:\WINDOWS\soundman.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

C:\Documents and Settings\All Users\「开始」菜单\程序\启动

+ InterVideo WinCinema Manager.lnkWinCinema Managerc:\program files\intervideo\common\bin\wincinemamgr.exe

C:\Documents and Settings\Owner\「开始」菜单\程序\启动

+ 腾讯QQ.lnkd:\program files\新建文件夹\qq.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ NTIECatcher ClassNet Transport IE Helper ModuleXid:\program files\xi\nettransport 2\ntiehelper.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ 联想File not found: http://www.legend.com

+ 腾讯QQd:\program files\新建文件夹\qq.exe

HKLM\System\CurrentControlSet\Services

+ NtFrs32c:\windows\system32\ntfrs32.exe

+ NVSvcNVIDIA Driver Helper Service, Version 28.32NVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys

+ basic2NTRksample driverConexantc:\windows\system32\drivers\hsf_bsc2.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSys瑞星c:\program files\rising\rav\hooksys.sys

+ HSF_DPHSF_DP driverConexant Systemsc:\windows\system32\drivers\hsf_dp.sys

+ hsf_msftWinACHSF driverConexantc:\windows\system32\drivers\hsf_msft.sys

+ HSFHWBS2HSF_HWB2 WDM driverConexant Systemsc:\windows\system32\drivers\hsfhwbs2.sys

+ kmsinputc:\windows\system32\drivers\kmsinput.sys

+ mdmxsdkDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\mdmxsdk.sys

+ MSJDrvrc:\windows\system32\drivers\msjdrvr.sys

+ New0c:\windows\system32\new.sys

+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 28.32 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RksampleRksample WDM driverConexantc:\windows\system32\drivers\hsf_samp.sys

+ RsFwDrvnt_fwdrvRisingc:\program files\rising\rfw\rsfwdrv.sys

+ rtl8139NDIS 5.0 driver                                                                  Realtek Semiconductor Corporation                                                c:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ sisagpSiS NT AGP FilterSilicon Integrated Systems Corporationc:\windows\system32\drivers\sisagpx.sys

+ SiSideSiS PCI Mini IDE DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\siside.sys

+ sisperfSiS Filter DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\sisperf.sys

+ UIUSysDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\uiusys.sys

+ winachsfWinACHSF driverConexant Systemsc:\windows\system32\drivers\hsf_cnxt.sys

+ ZSMC303Video streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm303.sys

gototop
 

O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [mstasks.exe] C:\WINDOWS\System32\mstasks.exe

修复
重启
删除C:\WINDOWS\System32\mstasks.exe;C:\WINDOWS\htpatch.exe试试

我按照这个方法修复了,但是因为我不知道找到的是不是就是你说 的那个,所以我还没删除了
gototop
 

我看了一下mstasks.dll的属性,它的创建时间是我组装电脑的时间,能删除吗?
gototop
 

HKLM\System\CurrentControlSet\Services

+ NtFrs32c:\windows\system32\ntfrs32.exe

+ New0c:\windows\system32\new.sys
+ MSJDrvrc:\windows\system32\drivers\msjdrvr.sys

删除启动项
重启
删除c:\windows\system32\ntfrs32.exe;
c:\windows\system32\new.sys;
c:\windows\system32\drivers\msjdrvr.sys
gototop
 

按照方法删除启动项,重起后只找着c:\windows\system32\drivers\msjdrvr.sys,删除了,其他两个地址c:\windows\system32\ntfrs32.exe;
c:\windows\system32\new.sys;根本没有,是不是删除启动项以后没有的,因为删除之前我还找着了,可是删除以后,重起电脑就没有了,这样就好了吗?这次重起电脑到是没有黄页出现了.
gototop
 
12345   4  /  5  页   跳转
页面顶部
Powered by Discuz!NT