瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 偶的电脑上Trojan.PSW.QQPass.qaa这个病毒,各位帮偶下啊有日志

1   1  /  1  页   跳转

偶的电脑上Trojan.PSW.QQPass.qaa这个病毒,各位帮偶下啊有日志

偶的电脑上Trojan.PSW.QQPass.qaa这个病毒,各位帮偶下啊有日志

当前运行的进程:         
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
D:\瑞星杀毒\Rav\CCenter.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
E:\WINDOWS\System32\drivers\CDAC11BA.EXE
E:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\spool\ugplot\ugiipqd.exe
E:\Program Files\UG\License Servers\UGNXFLEXlm\lmgrd.exe
E:\Program Files\UG\License Servers\UGNXFLEXlm\uglmd.exe
E:\WINDOWS\Explorer.EXE
D:\瑞星杀毒\Rav\RavTask.exe
E:\Program Files\Tencent\QQ\TIMPlatform.exe
E:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
E:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
D:\瑞星杀毒\Rav\Ravmond.exe
D:\瑞星杀毒\Rav\RAVMON.EXE
D:\瑞星杀毒\Rav\RavStub.exe
E:\Program Files\Tencent\QQ\QZone\QZone.exe
E:\Program Files\Internet Explorer\iexplore.exe
D:\瑞星杀毒\Rav\Rav.exe
最后编辑2006-09-18 15:59:37
分享到:
gototop
 

E:\Program Files\Tencent\QQ\TIMPlatform.exe
E:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
E:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
D:\瑞星杀毒\Rav\Ravmond.exe
D:\瑞星杀毒\Rav\RAVMON.EXE
D:\瑞星杀毒\Rav\RavStub.exe
E:\Program Files\Tencent\QQ\QZone\QZone.exe
E:\Program Files\Internet Explorer\iexplore.exe
D:\瑞星杀毒\Rav\Rav.exe
E:\DOCUME~1\SHW\LOCALS~1\Temp\test.exe
E:\Program Files\Tencent\QQ\QQ.exe
E:\WINDOWS\System32\conime.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Super Rabbit\IEG\winspeed.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\董设\HijackThis1991zww.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - E:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - E:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - E:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - E:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - E:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - E:\Program Files\Yahoo!\Assistant\Assist\yassist.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4A40-8DFD-58B0666ABEBD} - E:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - E:\WINDOWS\System32\kakatool.dll
O4 - 启动项HKLM\\Run: [RavTask] "D:\瑞星杀毒\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) - res://E:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://E:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/203
O9 - 浏览器额外的按钮: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O10 - Broken Internet access because of LSP provider 'e:\windows\system32\cdnns.dll' missing
O11 - Options group: [!CNS]  中文上网
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBE443A7-753E-41CC-A680-A44550A17863}: NameServer = 202.96.104.17,202.96.104.16
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - NT 服务: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - E:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - NT 服务: C-DillaCdaC11BA - Macrovision - E:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - NT 服务: C-DillaSrv - C-Dilla Ltd - E:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - NT 服务: ELSA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒\Rav\Ravmond.exe
O23 - NT 服务: Unigraphics Plot Server (ugiipqd) (ugiipqd) - Unigraphics Solutions, Inc - E:\WINDOWS\System32\spool\ugplot\ugiipqd.exe
O23 - NT 服务: Unigraphics License Server (uglmd) - Macrovision Corporation - E:\Program Files\UG\License Servers\UGNXFLEXlm\lmgrd.exe
O23 - NT 服务: win32 - Unknown owner - E:\WINDOWS\system.exe (file missing)
gototop
 

各位帮偶啊
gototop
 

看本论坛超级主题贴的第三个帖子
gototop
 

偶不会操作,找不到那个病毒藏的地方没有那个文件夹
gototop
 

引用:
【lianlian201的贴子】偶不会操作,找不到那个病毒藏的地方没有那个文件夹
………………

用icesword(冰刃),帖子中提到的,那个帖子已经说的很详细了
gototop
 

还有Trojan.LowZones.akx这个
gototop
 

O23 - NT 服务: win32 - Unknown owner - E:\WINDOWS\system.exe (file missing)
打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索win32 删除...

安全模式下清空
E:\DOCUME~1\SHW\LOCALS~1\Temp\

http://download5.pctutu.com/soft/winspeed782.zip
用超级兔子清理王在安全模式下卸载流氓软件...
gototop
 

打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索win32 删除...
注册表编辑器在哪啊
gototop
 

qiuzhu a
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT