`
caobihole
  • 浏览: 952071 次
文章分类
社区版块
存档分类
最新评论

遭遇Trojan.PSW.Lmir.kyo、Trojan.DL.QQHelper等N多木马

 
阅读更多

endurer 原创

2006-09-23 第1

有位网友的电脑经常发现病毒,手动扫描也清除不干净。
让我帮忙检查一下。

http://endurer.ys168.com 下载HijackThis扫描log,发现以下可疑项:

/----------
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 0:30:24, 日期 2006-9-19
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:
C:/PROGRA~1/svhost32.exe

F3 - REG:win.ini: load=C:/PROGRA~1/svhost32.exe
O2 - BHO: AdPopup - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} - C:/Program Files/Common Files/CPUSH/cpush.dll
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:/Documents and Settings/All Users/Application Data/Microsoft/IEHelper/IEHelper2006814_4593.dll (file missing)
O2 - BHO: (no name) - {3A134B8D-CA84-42A9-BF88-CE45F8C395BF} - C:/WINDOWS/system32/IEOPENGL.DLL
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:/PROGRA~1/CNNIC/Cdn/cdnforie.dll
O2 - BHO: (no name) - {8532B305-4486-4388-939F-341C0430CDFC} -
C:/WINDOWS/system32/DxBho.dll
O2 - BHO: QuickBtn - {D1BB7CF4-4463-4e91-88D7-ECC3CE0A13B7} - C:/Program Files/kuzhan/kuzhan.dll
O2 - BHO: (no name) - {D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF} - (no file)
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:/PROGRA~1/CNNIC/Cdn/wmhlpr.dll

O4 - 启动项HKLM//Run: [Update] C:/Program Files/Common Files/UPDATE2/Update.exe (kuzhan的项目)
O4 - 启动项HKLM//Run: [CdnCtr] C:/Program Files/CNNIC/Cdn/cdnup.exe
O4 - 启动项HKCU//Run: [updatereal] C:/WINDOWS/realupdate.exe other
O4 - 启动项HKCU//Run: [msnnt] C:/WINDOWS/winampa.exe

O8 - IE右键菜单中的新增项目: 用炫彩图铃发送该图片 - C:/Program Files/CaiShow Tech/CaiShow/SendMMS.htm
O8 - IE右键菜单中的新增项目: 访问通用网址 - C:/Program Files/CNNIC/Cdn/cnnic.htm
O9 - 浏览器额外的按钮: 酷站导航 - {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} - C:/Program Files/kuzhan/kuzhan.dll
O9 - 浏览器额外的按钮: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:/PROGRA~1/CNNIC/Cdn/cdnforie.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:/PROGRA~1/CNNIC/Cdn/cdnforie.dll

O10 - 未知的文件在 Winsock LSP: c:/windows/system32/cdnns.dll

O11 - Options group: [CDNCLIENT] 中文上网

O23 - NT 服务: Network Logon (NetWorkLogon) - Unknown owner - rundll32.exe (file missing)

http://endurer.ys168.com 下载 并 运行 procview,终止进程:C:/PROGRA~1/svhost32.exe
----------/

停止并禁用服务: Network Logon (NetWorkLogon),其命令行是:rundll32.exe KB896475.log,start

C:/WINDOWS/system32>dir KB896475.log
驱动器 C 中的卷没有标签。
卷的序列号是 1013-3AFE

C:/WINDOWS/system32 的目录

2006-09-18 13:41 123,141 KB896475.log
1 个文件 123,141 字节


用WinRAR寻找下列文件:

C:/PROGRA~1/svhost32.exe(Kaspersky 报为 Trojan-PSW.Win32.Lineage.ahq
c:/windows/system32/dllwm.dll(Kaspersky 报为 Trojan-PSW.Win32.Lineage.ahq
c:/windows/system32/TIMPlatforms.exe
c:/windows/system32/KB896475.log(瑞星报为 Trojan.PSW.Lmir.kyo


STATUS: FINISHED
Complete scanning result of "KB896475.log.del", received in VirusTotal at 09.18.2006, 19:28:23 (CET).

Antivirus Version Update Result
AntiVir 7.2.0.16 09.18.2006 no virus found
Authentium 4.93.8 09.18.2006 no virus found
Avast 4.7.844.0 09.15.2006 Win32:Wow-X
AVG 386 09.18.2006 no virus found
BitDefender 7.2 09.18.2006 no virus found
CAT-QuickHeal 8.00 09.18.2006 no virus found
ClamAV devel-20060426 09.18.2006 no virus found
eTrust-InoculateIT 23.72.127 09.16.2006 no virus found
eTrust-Vet 30.3.3084 09.18.2006 no virus found
DrWeb 4.33 09.18.2006 no virus found
Ewido 4.0 09.18.2006 no virus found
Fortinet 2.82.0.0 09.18.2006 suspicious
F-Prot 3.16f 09.18.2006 Possibly a new variant of W32/Threat-IKNP-based!Maximus
F-Prot4 4.2.1.29 09.18.2006 W32/Threat-IKNP-based!Maximus
Ikarus 0.2.65.0 09.18.2006 Backdoor.Win32.PcClient.GV
Kaspersky 4.0.2.24 09.18.2006 no virus found
McAfee 4854 09.18.2006 no virus found
Microsoft 1.1560 09.17.2006 no virus found
NOD32v2 1.1761 09.18.2006 no virus found
Norman 5.80.02 09.18.2006 no virus found
Panda 9.0.0.4 09.18.2006 Suspicious file
Sophos 4.09.0 09.18.2006 no virus found
Symantec 8.0 09.18.2006 no virus found
TheHacker 6.0.1.071 09.17.2006 no virus found
UNA 1.83 09.18.2006 no virus found
VBA32 3.11.1 09.18.2006 no virus found
VirusBuster 4.3.7:9 09.18.2006 no virus found

Aditional Information
File size: 123141 bytes
MD5: 25ea5d35320afb7a4343bed7e205a25c
SHA1: 3a7a6c51873a60f8e327c2e1da41246c6d8f9f47
Packers: Packed

C:/WINDOWS/system32/DxBho.dll

STATUS: FINISHEDComplete scanning result of "dxbho.dll", received in VirusTotal at 09.18.2006, 18:45:58 (CET).

Antivirus Version Update Result
AntiVir 7.2.0.16 09.18.2006 no virus found
Authentium 4.93.8 09.18.2006 no virus found
Avast 4.7.844.0 09.15.2006 no virus found
AVG 386 09.18.2006 no virus found
BitDefender 7.2 09.18.2006 no virus found
CAT-QuickHeal 8.00 09.18.2006 no virus found
ClamAV devel-20060426 09.18.2006 no virus found
DrWeb 4.33 09.18.2006 no virus found
eTrust-InoculateIT 23.72.127 09.16.2006 no virus found
eTrust-Vet 30.3.3084 09.18.2006 no virus found
Ewido 4.0 09.18.2006 no virus found
Fortinet 2.82.0.0 09.18.2006 no virus found
F-Prot 3.16f 09.18.2006 no virus found
F-Prot4 4.2.1.29 09.18.2006 no virus found
Ikarus 0.2.65.0 09.18.2006 no virus found
Kaspersky 4.0.2.24 09.18.2006 no virus found
McAfee 4854 09.18.2006 no virus found
Microsoft 1.1560 09.17.2006 no virus found
NOD32v2 1.1761 09.18.2006 no virus found
Norman 5.90.23 09.18.2006 no virus found
Panda 9.0.0.4 09.18.2006 no virus found
Sophos 4.09.0 09.18.2006 no virus found
Symantec 8.0 09.18.2006 no virus found
TheHacker 6.0.1.071 09.17.2006 no virus found
UNA 1.83 09.18.2006 no virus found
VBA32 3.11.1 09.18.2006 no virus found
VirusBuster 4.3.7:9 09.18.2006 no virus found


Aditional Information
File size: 234496 bytes
MD5: 721f35dbcd412eb68653092845186048
SHA1: a2bcd6ba5246412323211072909412b9e75fb576
packers: UPX

C:/WINDOWS/system32/IEOPENGL.DLL

STATUS: FINISHEDComplete scanning result of "IEOPENGL.DLL", received in VirusTotal at 09.18.2006, 19:01:37 (CET).

Antivirus Version Update Result
AntiVir 7.2.0.16 09.18.2006 no virus found
Authentium 4.93.8 09.18.2006 no virus found
Avast 4.7.844.0 09.15.2006 no virus found
AVG 386 09.18.2006 no virus found
BitDefender 7.2 09.18.2006 no virus found
CAT-QuickHeal 8.00 09.18.2006 no virus found
ClamAV devel-20060426 09.18.2006 no virus found
DrWeb 4.33 09.18.2006 no virus found
eTrust-InoculateIT 23.72.127 09.16.2006 no virus found
eTrust-Vet 30.3.3084 09.18.2006 no virus found
Ewido 4.0 09.18.2006 no virus found
Fortinet 2.82.0.0 09.18.2006 no virus found
F-Prot 3.16f 09.18.2006 no virus found
F-Prot4 4.2.1.29 09.18.2006 no virus found
Ikarus 0.2.65.0 09.18.2006 no virus found
Kaspersky 4.0.2.24 09.18.2006 no virus found
McAfee 4854 09.18.2006 no virus found
Microsoft 1.1560 09.17.2006 no virus found
NOD32v2 1.1761 09.18.2006 no virus found
Norman 5.90.23 09.18.2006 no virus found
Panda 9.0.0.4 09.18.2006 no virus found
Sophos 4.09.0 09.18.2006 no virus found
Symantec 8.0 09.18.2006 no virus found
TheHacker 6.0.1.071 09.17.2006 no virus found
UNA 1.83 09.18.2006 no virus found
VBA32 3.11.1 09.18.2006 no virus found
VirusBuster 4.3.7:9 09.18.2006 no virus found


Aditional Information
File size: 233984 bytes
MD5: b430c5978fe008802e9d269901ef9980
SHA1: 7884f2469eff2f55d174ff7c5ad338731db54787
packers: UPX

C:/WINDOWS/system32/0848/baisoa>dir /s /a
驱动器 C 中的卷没有标签。
卷的序列号是 1013-3AFE

C:/WINDOWS/system32/0848/baisoa 的目录

2006-09-17 13:26 <DIR> .
2006-09-17 13:26 <DIR> ..
2006-09-18 13:40 71 up.dat
2006-09-17 13:26 229 verx.dat
2006-09-08 10:59 12,288 novel.exe
2006-09-15 14:14 20,992 dllhosta.dll
2006-09-17 13:26 <DIR> update
2006-09-17 13:26 69 updatefile.lst
2006-09-17 13:27 0 waitdown.lst
2006-09-17 13:27 90,112 avpa.exe
2006-09-18 13:40 18,432 winampa.exe
2006-09-18 13:40 465 adout.dat
9 个文件 142,658 字节

C:/WINDOWS/system32/0848/baisoa/update 的目录

2006-09-17 13:26 <DIR> .
2006-09-17 13:26 <DIR> ..
2006-09-18 13:40 71 up.dat
2006-09-17 13:26 69 updatefile.lst
2006-09-17 13:27 0 waitdown.lst
2006-09-17 13:26 229 verx.dat
2006-09-17 13:27 90,112 avpa.exe
2006-09-18 13:40 465 adout.dat
2006-09-18 13:40 18,432 winampa.exe
7 个文件 109,378 字节

所列文件总数:
16 个文件 252,036 字节
5 个目录 1,359,462,400 可用字节


http://endurer.ys168.com 下载并运行 瑞星杀毒助手,使用瑞星在线病毒扫描 C:/,结果如下:

/----------
2006-9-19 4:5:15 瑞星杀毒助手
Windows XP Service Pack 2(5.1.2600)
文件名 病毒名
C:/WINDOWS/system32/spoolsv/spoolsv.exe Trojan.DL.Agent.kij
C:/WINDOWS/system32/msicn/plugins/bm.dll Trojan.Ourxin.e
C:/WINDOWS/system32/msicn/plugins/as.dll Trojan.Ourxin.c
C:/WINDOWS/system32/msicn/msibm.dll Trojan.Spy.Agent.bhs
C:/WINDOWS/system32/1116/ntjdo/ntjcn.emm Trojan.Spy.Agent.bhs
C:/WINDOWS/system32/1116/ntjdo/plugins/cn.emm Trojan.Ourxin.e
C:/WINDOWS/system32/1116/ntjdo/plugins/bt.emm Trojan.Ourxin.c
C:/WINDOWS/system32/1116/tzt/xnqesn.emm Trojan.Ourxin.d
C:/WINDOWS/system32/1116/tqppmtw/tqppmtw.fyf Trojan.DL.Agent.kij
C:/WINDOWS/system32/0848/baisoa/update/winampa.exe>>Unpack Trojan.DL.Agent.ldt
C:/WINDOWS/system32/0848/baisoa/winampa.exe>>Unpack Trojan.DL.Agent.ldt
C:/WINDOWS/system32/wmpdrm.dll Trojan.Ourxin.d
C:/WINDOWS/system32/WinSC.dll Trojan.Clicker.Qhost.i
C:/WINDOWS/system32/WinSC64.dll Trojan.Clicker.Qhost.i
C:/WINDOWS/system32/UpdateModule.dll.del Trojan.Clicker.Agent.ads
C:/WINDOWS/system32/KB896475.log.del>>NsPack Trojan.PSW.Lmir.kyo
C:/WINDOWS/system32/ejjf.dll.del Trojan.DL.Direct.aa
C:/WINDOWS/system32/icif.dll.del Trojan.DL.Direct.aa
C:/WINDOWS/system32/jjbi.dll.del Trojan.DL.Direct.aa
C:/WINDOWS/system32/ijcj.dll.del Trojan.DL.Direct.aa
C:/WINDOWS/101628.exe.del Trojan.DL.ADLoad.ei
C:/WINDOWS/10045_setup.exe.del Trojan.StartPage.bnx

C:/Documents and Settings/All Users/Application Data/Microsoft/Crypto/dffj.exe.del Trojan.Inject.st
C:/Documents and Settings/All Users/Application Data/Tencent/bind_40040.exe Trojan.DL.Agent.lpu
C:/Documents and Settings/All Users/Application Data/Tencent/bind_40017.exe Trojan.DL.Agent.lpu
C:/Documents and Settings/All Users/Application Data/Tencent/setup72.exe Dropper.TiHs.g

C:/Program Files/Common Files/UPDATE2/Update.exe.1 Trojan.DL.QQHelper.efh
C:/Program Files/Windows Media Player/setup_wm.dll Trojan.DL.Agent.aph
C:/Program Files/Internet Explorer/iedw.dll Trojan.DL.Agent.aph
C:/Program Files/Common Files/System/ddcckl.dat Trojan.Inject.st
C:/Program Files/NetMeeting/nmview.dll Trojan.Agent.dte
C:/Program Files/NetMeeting/conf.dll Trojan.Agent.dte
C:/Program Files/xerox/fcbzc.exe Trojan.Inject.st
C:/Program Files/CNNIC/iebar_v2.exe Trojan.DL.QQHelper.eo

C:/nxldr.dat>>NsPack Trojan.PSW.Lmir.kyo
----------/

打包备份后,用瑞星杀毒助手清除。

关闭所有浏览器和文件夹窗口,用HijackThis扫描并修复上面所列项目。

清空IE临时文件夹

清空 c:/Documents and Settings/user/Local Settings/temp(其中 user 为用户名)

清空 c:/windows/temp

分享到:
评论

相关推荐

    Trojan.Locker.8感染文件解锁工具tl08unlock

    俄罗斯安全软件Dr.Web,Trojan. Plastix木马感染文件解除工具plstfix

    Trojan专杀工具,用着真不错.

    Trojan专杀工具,用着真不错;我在网上找了好长时间才长到的,愿意与大家一块来分享.另外,本人是教育行业的,分享一个好的英语资料下载站:http://www.51tjw.com

    安铁诺Trojan.VBS.StartPage.dy专杀 V2010.exe

    安铁诺Trojan.VBS.StartPage.dy专杀 V2010.exe。针对1KB病毒

    敲诈者(Trojan.Disclies.e)解决方案

    敲诈者木马程序以敲诈勒索钱财为目的,使得感染该木马的计算机用户系统中的指定数据文件被恶意隐藏,造成用户数据丢失。截至目前为止,在国内已经出现了因感染该木马程序而导致计算机系统数据文件丢失的情况。该木马...

    Trojan. Plastix解除工具plstfix

    俄罗斯安全软件大蜘蛛Dr.Web,木马解锁工具.

    USBCleaner6.0

    RECYCLER.exe变种,GHOST.PIF变种,KPE.exe(EKS.exe) Trojan.DL.VB.nua,services.exe变种,sysauto.exe变种,myserver变种,pegefile.pif(Trojan.PSW.Win32.Agent.mk), autorun.exe (Worm.Win32.Agent.h)等

    2020年trojan最新windows64客户端trojan-1.15.1-win.zip

    2020年trojan最新windows64客户端

    Trojan-Downloader.Win32.Generic.a...

    【病毒名称】:Trojan-Downloader.Win32.Generic.a 【病毒类型】:下载者 【危害程度】:中 【传播方式】:网络 【受影响系统】:windows 98以上 病毒行为: 该病毒为下载者木马类,病毒运行后调用API获取系统文件夹...

    js.scob.trojan.nasl

    js.scob.trojan

    最新杀毒木马程序(new)

    可查杀最新木马,主要用于查杀Trojan.Malscript!html等易中木马

    假冒TXPLATFORM.EXE 的U盘病毒

    我的电脑让学生插了一下U盘,结果电脑出现中毒现象(变慢、经常蓝屏、出错、自动重启),一查是染上了 假冒腾迅TXPLATFORM.EXE 的U盘病毒,属于 Trojan.Generic.Is.536802,此文介绍查杀方法

    Trojan-Dropper.Win32.Dropkit.a清除工具

    针对Trojan-Dropper.Win32.Dropkit.a病毒,清除所需要的工具包,包括金山反间谍2007、PowerRmv、sreng2.5

    Android代码-Trojan

    Trojan is a stable and efficient mobile lightweight log SDK that not only records general logs, such as Http, power changes, component life cycles, but also records the definition of the log, which it...

    Trojan Killer(木马查杀工具) v2.2.2.6中文免费版.zip

    Gridinsoft Trojan Killer木马克星是专门来禁用/删除没有用户不必手动编辑系统文件或注册表的恶意软件。该方案还删除一些恶意软件进行了一些标准的防病毒扫描器忽略额外的系统修改。   Trojan Killer扫描所有的...

    流行病毒统杀工具 2006 v1.0.0

    本软件用于查杀各类已知或未知的...QQ密码使者、 QQ密码大盗、Trojan.QQSender.nicex、 Trojan.QQSender.ok530、 Trojan.QQSender.qiumei、Trojan.QQSender.qq3344 等2300余种病毒、木马测试,查杀准确率达98%以上!

    trojan-qt5.app.zip

    trojan-qt5.app.zip

    trojan-qt5.tar.gz

    trojan-qt5 for linux

    技佳重庆电脑维修-清理垃圾与系统优化

    技佳重庆电脑维修-清理垃圾与系统优化 重庆电脑维修,重庆家电脑维修 ... ==========本程序功能有...1 能很快地清理垃圾文件 2 清除右键自动播放 3 auto病毒 4 Delete Trojan.PSW.Lmir.iux By o__4pollo 5 设IE首页与标题

Global site tag (gtag.js) - Google Analytics