瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的电脑中了trojan.agent.eg 怎么办,(求救)

12   2  /  2  页   跳转

我的电脑中了trojan.agent.eg 怎么办,(求救)

2006-09-08,21:05:08

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

gototop
 

2006-09-08,21:05:08

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <rx><C:\WINDOWS\system32\explore.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <!ewido><"C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized>  [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <mmsk><D:\tools\木马杀客\mmsk.exe>  [木马杀客]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    <WinlogonNotify: AtiExtEvent><Ati2evxx.dll>  [ATI Technologies Inc.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\friends1.scr>  [MacSourcery]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <!ewido><; "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized>  [Anti-Malware Development a.s.]
    <ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <ccApp><; "C:\Program Files\Common Files\Symantec Shared\ccApp.exe">
gototop
 

[Symantec Corporation]
    <EPSON Stylus C63 Series><; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C63 Series" /O6 "USB001" /M "Stylus C63">  [SEIKO EPSON CORPORATION]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <nTrayFw><; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe>  [NVIDIA Corporation]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <SoundMan><; SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]

==================================
启动文件夹
[Adobe Gamma Loader]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
[Microtek 扫描仪探测器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microtek 扫描仪探测器.lnk><N>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Symantec Event Manager / ccEvtMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
  <C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[ForceWare Intelligent Application Manager (IAM) / ForceWare Intelligent Application Manager (IAM)]
  <C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe><>
[Forceware Web Interface / ForcewareWebInterface]
  <"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice><Apache Software Foundation>
[Norton AntiVirus Auto-Protect Service / navapsvc]
  <"C:\Program Files\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[Norton AntiVirus Firewall Monitor Service / NPFMntor]
  <"C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe"><Symantec Corporation>
[ForceWare IP service / nSvcIp]
  <C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe><NVIDIA>
[ForceWare user log service / nSvcLog]
  <C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe><NVIDIA>
[SAVScan / SAVScan]
gototop
 

Corporation>
[Symantec SPBBCSvc / SPBBCSvc]
  <"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec Core LC / Symantec Core LC]
  <C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe><Symantec Corporation>

==================================
浏览器加载项
[CNavExtBho Class]
  {BDF3E430-B101-42AD-A544-FADC6B084872} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Norton AntiVirus]
  {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[HostranBar]
  {88F2B391-8D09-4c0e-9824-5ECD0F382f66} <C:\WINDOWS\Hostran\HostranBar.DLL, >
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Norton AntiVirus]
  {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[raObject Class]
  {46F194EB-B7DB-4B7A-BD42-5FF39FD17664} <C:\PROGRA~1\pcast\hbcast.dll, N/A>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[HostranBar]
  {88F2B391-8D09-4C0E-9824-5ECD0F382F66} <C:\WINDOWS\Hostran\HostranBar.DLL, >
[CNavExtBho Class]
  {BDF3E430-B101-42AD-A544-FADC6B084872} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>

==================================
正在运行的进程
[PID: 536][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 608][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 672][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\Ati2evxx.dll]  <ATI Technologies Inc.><6.14.10.4116>
[PID: 732][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 744][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 908][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4116>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 948][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1032][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1132][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1212][C:\WINDOWS\system32\svchost.exe]  <Microsoft
gototop
 

<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1256][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1448][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\EBPMON24.DLL]  <SEIKO EPSON CORPORATION><1, 4, 0, 0>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DU18CE.DLL]  <SEIKO EPSON Corporation><0. 3. 0, 76>
[PID: 1628][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4116>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 1888][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Norton AntiVirus\NavShExt.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccL30.dll]  <Symantec Corporation><103.0.7.2>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\ewido anti-spyware 4.0\context.dll]  <Anti-Malware Development a.s.><4, 0, 0, 172>
[PID: 416][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 516][C:\Program Files\Norton AntiVirus\navapsvc.exe]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Norton AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.4.1.10>
[PID: 572][C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe]  <><1, 0, 0, 1>
    [C:\Program Files\Microtek\ScanWizard 5\SFRes.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Microtek\ScanWizard 5\scanners\Msmgr32.dll]  <N/A><N/A>
    [C:\Program Files\Microtek\ScanWizard 5\scanners\MS32RES.DLL]  <N/A><N/A>
    [C:\Program Files\Microtek\ScanWizard 5\scanners\MPHASE32.DLL]  <N/A><N/A>
    [C:\Program Files\Microtek\ScanWizard 5\scanners\MSSTI.DLL]  <Microtek International Inc.><1.62.4>
    [C:\Program Files\Microtek\ScanWizard 5\scanners\SM8B32.DLL]  <Microtek International Inc.><1.02>
[PID: 580][C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccL30.dll]  <Symantec Corporation><103.0.7.2>
[PID: 800][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\MSMWUD.DLL]  <Microtek International Inc.><1.08.1>
    [C:\WINDOWS\system32\MSM8bW.DLL]  <Microtek International Inc.><1.02>
[PID: 1340][C:\Program Files\NVIDIA
gototop
 

Corporation><103.0.7.2>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.0.7.2>
[PID: 2364][D:\tools\ACDSEE32\ACDSEE32.EXE]  <ACD Systems, Ltd.><2, 2, 2, 0>
    [D:\tools\ACDSEE32\DC210_32.dll]  <Eastman Kodak Company><0, 2, 0, 3>
    [C:\Program Files\Common Files\Adobe\Shell\PSICON.DLL]  <Adobe Systems, Incorporated><7.0>
[PID: 3944][C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe]  <Adobe Systems, Incorporated><7.0.1>
    [C:\Program Files\Adobe\Photoshop 7.0\ACE.dll]  <Adobe Systems Incorporated><2.02.05>
    [C:\Program Files\Adobe\Photoshop 7.0\AGM.dll]  <Adobe Systems Incorporated><4.08.18>
    [C:\Program Files\Adobe\Photoshop 7.0\BIB.dll]  <Adobe Systems Incorporated><1.1.8>
    [C:\Program Files\Adobe\Photoshop 7.0\CoolType.dll]  <Adobe Systems Incorporated><4.10.20>
    [C:\Program Files\Adobe\Photoshop 7.0\asn.er.dll]  <N/A><N/A>
    [C:\Program Files\Adobe\Photoshop 7.0\Photoshop.dll]  <Adobe Systems, Incorporated><7.0.1>
    [C:\Program Files\Adobe\Photoshop 7.0\PSViews.dll]  <Adobe Systems, Incorporated><7.0.1>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DU18CE.DLL]  <SEIKO EPSON Corporation><0. 3. 0, 76>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_DMAI16.DLL]  <SEIKO EPSON Corporation><0. 3. 3. 7>
    [C:\Program Files\Adobe\Photoshop 7.0\Plug-Ins\Adobe Photoshop Only\Extensions\FastCore.8BX]  <Adobe Systems, Incorporated><7.0.1>
    [C:\Program Files\Adobe\Photoshop 7.0\PLUGIN.dll]  <Adobe Systems, Incorporated><7.0>
    [C:\Program Files\Adobe\Photoshop 7.0\Plug-Ins\Adobe Photoshop Only\Extensions\MMXCore.8BX]  <Adobe Systems, Incorporated><7.0.1>
    [C:\Program Files\Adobe\Photoshop 7.0\Required\ADMPlugin.apl]  <Adobe Systems Incorporated><2.84ps79 07.15.2002-10:05:00h>
    [C:\Program Files\Adobe\Photoshop 7.0\Required\PNGIcons.apl]  <Adobe Systems Incorporated><1.21x7 2001.12.14-1602h.21s>
    [C:\Program Files\Adobe\Photoshop 7.0\Required\ASDataStream.apl]  <Adobe Systems Incorporated><1.02x7 02.02.15-01:45:06h>
    [C:\Program Files\Adobe\Photoshop 7.0\Plug-Ins\Parser\PDF 图像导入.8BI]  <Adobe Systems, Incorporated><7.0.1>
    [C:\Program Files\Adobe\Photoshop 7.0\PDFL50.dll]  <Adobe Systems Incorporated><5.0.000>
    [C:\Program Files\Adobe\Photoshop 7.0\OPP.dll]  <Adobe Systems Incorporated><1.02.01>
    [C:\WINDOWS\system32\ATMLIB.dll]  <Adobe Systems><5.1 Build 226>
    [C:\Program Files\Common Files\Adobe\Workflow\ARM.dll]  <Adobe Systems, Incorporated><2.8.3.3>
    [C:\Program Files\Common Files\Adobe\Web\AdobeWeb.dll]  <Adobe Systems, Incorporated><2.8.3.3>
gototop
 


  <"C:\Program Files\Norton AntiVirus\SAVScan.exe"><Symantec Corporation>
[ScriptBlocking Service / SBService]
  <C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc]
Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe]  <><1, 0, 1, 0>
    [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\NMI.dll]  <NVIDIA Corporation><2, 2, 0, 464>
    [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nv_common.dll]  <NVIDIA><2, 2, 0, 464>
    [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nv_resource_L1033.dll]  <NVIDIA Corporation><1, 0, 1, 0>
[PID: 392][C:\Program Files\FlashGet\flashget.exe]  <Amaze Soft><1, 4, 0, 0>
[PID: 1700][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2708][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3744][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Norton AntiVirus\NavShExt.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccL30.dll]  <Symantec
[PID: 224][D:\tools\ACDSEE32\ACDSEE32.EXE]  <ACD Systems, Ltd.><2, 2, 2, 0>
    [D:\tools\ACDSEE32\DC210_32.dll]  <Eastman Kodak Company><0, 2, 0, 3>
    [C:\Program Files\Common Files\Adobe\Shell\PSICON.DLL]  <Adobe Systems, Incorporated><7.0>
[PID: 2688][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 3112][C:\DOCUME~1\jia\LOCALS~1\Temp\Rar$EX00.797\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

日志漏了些吧。。。
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项
<rx><C:\WINDOWS\system32\explore.exe>
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,在隐藏文件和文件夹选项里选择显示所有文件和文件夹 清除“隐藏已知文件类型的扩展名
删除:
C:\WINDOWS\system32\explore.exe
gototop
 

不会少呀,我是用剪的,一次一次贴,太多木马了
gototop
 

安全模式清空IE临时文件,清空 C:\Documents and Settings\用户名\Local Settings\Temp ,C:\WINDOWS\Temp, C:\WINDOWS\Prefetch 文件夹
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT