瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Trojan.PSW.Lmir.lfn 怎么才能杀干净??高手救命,我已被盗两次!!

12   1  /  2  页   跳转

Trojan.PSW.Lmir.lfn 怎么才能杀干净??高手救命,我已被盗两次!!

Trojan.PSW.Lmir.lfn 怎么才能杀干净??高手救命,我已被盗两次!!


1。瑞星防火墙查到svchost.exe>>C:\WINDOWS\system32\svchost.exe ->Trojan.PSW.Lmir.lfn ;
2。自动生成 vpcrm.exe 到C:\WINDOWS\SYSTEM32\ 下;
  自动生成 usbme.sys 到C:\WINDOWS\SYSTEM32\drivers\下;
(见附件,cpcrm.exe 为隐藏文件不会复制)
3。自动添加注册表
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run                     
9              C:\WINDOWS\SYSTEM32\VPCRM.EXE   
 
4。HijackThis1.99.1扫描发现
O20 - AppInit_DLLs: APIhookdll.dll  (APIhookdll.dll windows却收索不到)
以上都删除后,重起仍发现木马,郁闷,高手指教啊!!!
最后编辑2006-11-02 21:07:22.263000000
分享到:
gototop
 

病毒文件不能上传
gototop
 

高手都睡了??
gototop
 

大大在不在,帮忙看看啊,不然我要重装了
gototop
 

大大有没在啊??
gototop
 

那是个隐藏文件,我只会在dos下删除,不知道怎么复制
gototop
 

usbme.sys 我到是backup了
gototop
 

dos下用del VPCRM.EXE /Ah 可以杀掉
gototop
 

引用:
【lingpeter的贴子】
你快把病毒样本发给斑竹!然后我好学解决的办法!对了DOS下如何杀?反正这个好象会感染QQ所以我把QQ都给杀掉了
………………

果然,我查到qq被感染!!晕死!!
gototop
 

大大帮忙看看我现在的日志,有没有什么问题,那个f2是个啥玩意??
Logfile of HijackThis v1.99.1
Scan saved at 22:54:39, on 2006-11-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Rising\Rav\RAVTASK.EXE
D:\Program Files\Rising\Rav\RavStub.exe
D:\Program Files\Iparmor\Iparmor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\conime.exe
d:\program files\rising\rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
F:\Tool\病毒查杀工具\HijackThis\248783200522382732\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O8 - Extra context menu item: 使用网际快车下载 - D:\PROGRA~1\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\PROGRA~1\FLASHGET\jc_all.htm
O9 - Extra button: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - Extra 'Tools' menuitem: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {DD713965-ECD7-407B-A886-FCF999BB6765} (SnSubmitControl Class) - http://jf.sdo.com/sndasec.cab
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT