瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:我中了木马"Trojan-Downloader.win32.QQHelper.mo"

1   1  /  1  页   跳转

求助:我中了木马"Trojan-Downloader.win32.QQHelper.mo"

求助:我中了木马"Trojan-Downloader.win32.QQHelper.mo"

一开机KK就说"C:\WINDOWS\system32\tgoqst62.dll"发现"Trojan-Downloader.win32.QQHelper.mo",然后重启后就删除,可重启后又说相同的说,反复弄了4次,该怎么杀?各位高手教教我啊!
最后编辑2006-10-22 21:45:48
分享到:
gototop
 

未发现: 木马程序 Trojan-Dropper.Win32.Delf.hl文件: E:\安装原文件\qq2006Beta2.exe.td/UPX
已检测到: 广告程序 not-a-virus:AdWare.Win32.Eztracks.bURL: http://union123.com/SearchCarxid.cab\SearchCar.dll
已检测到: 广告程序 not-a-virus:AdWare.Win32.Iebar.hURL: http://iebar.t2t2.com/iebar.cab\iebar23.0.dll
已检测到: 木马程序 Trojan-Downloader.JS.IstBar.aiURL: http://iptan.union.dofor.cn/pop/popup.asp?id=1793&url=http%3A//zhbx.xihai.com/bin/zhbx_zhbxjs-message-1339.html
已检测到: 木马程序 Trojan-Downloader.JS.IstBar.aiURL: http://www.2t2t.cn/popup.asp?id=1175&url=http%3A//yqzsf.com/Article/sadf/dta/200610/1925.html
已检测到: 木马程序 Trojan-Downloader.JS.IstBar.aiURL: http://union.jonweb.net/pop/popup.asp?id=84&url=http%3A//kj8.bxsz.net/soft/5/115/202/2006/200605232542.html
已检测到: 木马程序 Trojan-Downloader.VBS.Psyme.clURL: http://afied.com/d/ads.htm
已检测到: 木马程序 Trojan-Downloader.VBS.Small.boURL: http://www.17587.net/inc/1.htm
已检测到: 木马程序 Trojan-Downloader.Win32.QQHelper.mo文件: C:\WINDOWS\system32\tgoqst62.dll
已检测到: 木马程序 Trojan-Dropper.Win32.Delf.hlURL: http://www.qqqxz.com/down/qq2006Beta2.exe/UPX
已检测到: 木马程序 Trojan-PSW.Win32.Delf.qcURL: http://bbs.m369m.com/wwwmmm/112.exe/UPX
已删除: 病毒 Virus.Python.RJump.a文件: H:\Autorun.inf
已删除: 广告程序 not-a-virus:AdWare.Win32.Hmt文件: d:\program files\sdmz\40.exe
已删除: 广告程序 not-a-virus:AdWare.Win32.Hmt文件: D:\System Volume Information\_restore{8B9A8F7C-0920-4CC3-9DEC-FA3CCA620FE4}\RP14\A0003120.exe
已删除: 木马程序 Backdoor.Win32.Hupigon.bsw文件: c:\windows\yoaoo.com.ini/PE_Patch
已删除: 木马程序 Backdoor.Win32.Hupigon.bsw文件: C:\System Volume Information\_restore{8B9A8F7C-0920-4CC3-9DEC-FA3CCA620FE4}\RP11\A0003015.ini
gototop
 

未发现: 木马程序 Trojan-Dropper.Win32.Delf.hl文件: E:\安装原文件\qq2006Beta2.exe.td/UPX
已检测到: 广告程序 not-a-virus:AdWare.Win32.Eztracks.bURL: http://union123.com/SearchCarxid.cab\SearchCar.dll
已检测到: 广告程序 not-a-virus:AdWare.Win32.Iebar.hURL: http://iebar.t2t2.com/iebar.cab\iebar23.0.dll
已检测到: 木马程序 Trojan-Downloader.JS.IstBar.aiURL: http://iptan.union.dofor.cn/pop/popup.asp?id=1793&url=http%3A//zhbx.xihai.com/bin/zhbx_zhbxjs-message-1339.html
已检测到: 木马程序 Trojan-Downloader.JS.IstBar.aiURL: http://www.2t2t.cn/popup.asp?id=1175&url=http%3A//yqzsf.com/Article/sadf/dta/200610/1925.html
已检测到: 木马程序 Trojan-Downloader.JS.IstBar.aiURL: http://union.jonweb.net/pop/popup.asp?id=84&url=http%3A//kj8.bxsz.net/soft/5/115/202/2006/200605232542.html
已检测到: 木马程序 Trojan-Downloader.VBS.Psyme.clURL: http://afied.com/d/ads.htm
已检测到: 木马程序 Trojan-Downloader.VBS.Small.boURL: http://www.17587.net/inc/1.htm
已检测到: 木马程序 Trojan-Downloader.Win32.QQHelper.mo文件: C:\WINDOWS\system32\tgoqst62.dll
已检测到: 木马程序 Trojan-Dropper.Win32.Delf.hlURL: http://www.qqqxz.com/down/qq2006Beta2.exe/UPX
已检测到: 木马程序 Trojan-PSW.Win32.Delf.qcURL: http://bbs.m369m.com/wwwmmm/112.exe/UPX
已删除: 病毒 Virus.Python.RJump.a文件: H:\Autorun.inf
已删除: 广告程序 not-a-virus:AdWare.Win32.Hmt文件: d:\program files\sdmz\40.exe
已删除: 广告程序 not-a-virus:AdWare.Win32.Hmt文件: D:\System Volume Information\_restore{8B9A8F7C-0920-4CC3-9DEC-FA3CCA620FE4}\RP14\A0003120.exe
已删除: 木马程序 Backdoor.Win32.Hupigon.bsw文件: c:\windows\yoaoo.com.ini/PE_Patch
已删除: 木马程序 Backdoor.Win32.Hupigon.bsw文件: C:\System Volume Information\_restore{8B9A8F7C-0920-4CC3-9DEC-FA3CCA620FE4}\RP11\A0003015.ini
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      9:16:12, 日期 2006-10-19
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
D:\Program Files\木马清除专家 2006\mmqczj.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Tencent\TT\TTraveler.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
D:\讯雷下载\hijackthis\HijackThis1991zww.exe

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O2 - BHO: 搜搜地址栏搜索 - {0C7C23EF-A848-485B-873C-0ED954731014}? - (no file)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162}? - (no file)
O2 - BHO: BHObject Class - {AA2F655A-7618-499D-B0A5-4F84B91D2C5F} - C:\WINDOWS\system32\PCEggs.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AAC73F50-03DD-47E5-AD18-FDD65BF29E3D}? - (no file)
O2 - BHO: (no name) - {BBF3E65D-762A-41AC-BFDA-7C6D97E65A73}? - (no file)
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O3 - IE工具栏增项: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [Thunder] "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s
O4 - 启动项HKLM\\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [木马清除专家] d:\Program Files\木马清除专家 2006\mmqczj.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}? - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - 浏览器额外的按钮: PC蛋蛋 - {AA2F655A-7618-499D-B0A5-4F84B91D2C5F} - C:\WINDOWS\system32\PCEggs.dll
O9 - 浏览器额外的“工具”菜单项: PC蛋蛋 - {AA2F655A-7618-499D-B0A5-4F84B91D2C5F} - C:\WINDOWS\system32\PCEggs.dll
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - d:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - d:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的按钮: 易趣购物 - {DE607143-AC19-423e-860A-0D70ABDF119A}? - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {DE607143-AC19-423e-860A-0D70ABDF119A}? - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}? - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}? - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{BF6F0C8D-1D4C-4A39-8E7F-2BC566BB95A9}: NameServer = 10.0.2.1,10.0.2.5
O18 - 列举现有的协议: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - NT 服务: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: 卡巴斯基互联网安全套装 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

gototop
 

照你的方法做了一遍,可是还是说同样的话有这个木马,只要我点KK确定,删除,立刻就重启
gototop
 

是不是真的要重装斑竹?
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      10:01:50, 日期 2006-10-19
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Thunder Network\Thunder\ThunderShell.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
D:\Program Files\木马清除专家 2006\mmqczj.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
D:\Program Files\Tencent\TT\TTraveler.exe
C:\WINDOWS\system32\wuauclt.exe
D:\讯雷下载\hijackthis\HijackThis1991zww.exe

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O3 - IE工具栏增项: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [Thunder] "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s
O4 - 启动项HKLM\\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [木马清除专家] d:\Program Files\木马清除专家 2006\mmqczj.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}? - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - 浏览器额外的按钮: PC蛋蛋 - {AA2F655A-7618-499D-B0A5-4F84B91D2C5F} - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: PC蛋蛋 - {AA2F655A-7618-499D-B0A5-4F84B91D2C5F} - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - d:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - d:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - 浏览器额外的按钮: 易趣购物 - {DE607143-AC19-423e-860A-0D70ABDF119A}? - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {DE607143-AC19-423e-860A-0D70ABDF119A}? - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}? - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}? - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{BF6F0C8D-1D4C-4A39-8E7F-2BC566BB95A9}: NameServer = 10.0.2.1,10.0.2.5
O18 - 列举现有的协议: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - NT 服务: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: 卡巴斯基互联网安全套装 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

gototop
 

我已经好了,谢谢
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT