瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】关于trojan.startpage.tim病毒处理的问题

1   1  /  1  页   跳转

【原创】关于trojan.startpage.tim病毒处理的问题

【原创】关于trojan.startpage.tim病毒处理的问题

我遇到这个病毒。感染此病毒后,会每6分钟左右自动打开6个“iexplorer”窗口。用瑞星扫描出,手动清除的。不过好像并没彻底清除(见附图),现在会自动弹出“ie”错误,而且在任务管理器中还有“iexplorer”进程。
请高手能指点一下,不胜感激!!!

附件附件:

下载次数:176
文件类型:image/pjpeg
文件大小:
上传时间:2006-10-31 22:55:53
描述:



最后编辑2006-10-31 22:52:09
分享到:
gototop
 

下面是“瑞星听诊器”扫描后的信息




未知家族病毒分析
扫描结果:
无可疑文件


系统活动进程
C:\WINNT\SYSTEM32\HPZIPM12.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\MSD9EF44.DLL
C:\WINNT\SYSTEM32\MSVBVM50.DLL
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL

E:\SYS-BAK\RSDETECT.EXE
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL

C:\WINNT\SYSTEM32\INTERNAT.EXE
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL

C:\WINNT\EXPLORER.EXE
C:\WINNT\APPPATCH\ACLAYERS.DLL
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\WINNT\SYSTEM32\H9EF44F5.LOG
C:\WINNT\SYSTEM32\HC16B9B5.LOG
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV
C:\WINNT\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\FLASHGET\JCCATCH.DLL
C:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINNT\SYSTEM32\MSADP32.ACM
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL

C:\WINNT\SYSTEM32\TASKMGR.EXE
C:\WINNT\SYSTEM32\PINTLGNT.IME
C:\PROGRAM FILES\D9EF44F5\ED2C5B08.DLL


普通自启动项
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Internat.exe = INTERNAT.EXE


系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\Office\WINWORD.EXE" /n

其它启动项
WIN.INI
无信息

SYSTEM.INI
SHELL = Explorer.exe


Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

IE - BHO

Winsock SPI
MSAFD Irda [IrDA] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [TCP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [UDP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [RAW/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
RSVP UDP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B319B8F-5AD8-4F35-A85C-28E6B78D550C}] SEQPACKET 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B319B8F-5AD8-4F35-A85C-28E6B78D550C}] DATAGRAM 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{203F359B-EA80-415D-B0C2-FB285BBC3CF9}] SEQPACKET 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{203F359B-EA80-415D-B0C2-FB285BBC3CF9}] DATAGRAM 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2392D66-A9CA-47B6-8545-B6C54EAE136C}] SEQPACKET 2 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2392D66-A9CA-47B6-8545-B6C54EAE136C}] DATAGRAM 2 = C:\WINNT\SYSTEM32\MSAFD.DLL

系统服务项

文件驱动

系统驱动项

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT