|
发表于 2006-9-12 14:25:50
|
显示全部楼层
发几个木马查杀的方法吧,希望对大家有用
O23 - Service: Messenger - Unknown owner - C:\WINDOWS\system32\AUTOEXEC.BAT (file missing)
O23 - Service: Microsoft Winsock5 Service - Unknown owner - C:\WINDOWS\Microsoft Winsock5.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\发信息.exe (file missing)
O23 - Service: sys - Unknown owner - C:\WINDOWS\988510
O23 - Service: system - Unknown owner - C:\WINDOWS\system.exe
鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索Messenger
Microsoft Winsock5 Service
Schedule
sys 和 system 删除...
删除
C:\WINDOWS\988510
C:\WINDOWS\system.exe
C:\WINDOWS\Microsoft Winsock5.exe
修复
R3 - URLSearchHook: (no name) - {51707E60-11C0-44FB-BAC8-83EB0C93651C} - C:\WINDOWS\system32\Feve.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: 61.188.38.64 www.gamezt.com.cn
O1 - Hosts: 61.188.38.64 meng.nicemm.cn
O1 - Hosts: 61.188.38.64 upd.etsoft.com.cn
O1 - Hosts: 61.188.38.64 www.essonarts.com
O1 - Hosts: 61.188.38.64 ert0003.e76.163ns.com
O1 - Hosts: 61.188.38.64 sky001.e11.163ns.com
O1 - Hosts: 61.188.38.64 woool.100888290cs.com
O1 - Hosts: 61.188.38.64 rxjh.100888290cs.com
O1 - Hosts: 61.188.38.64 www.yowoool.com
O1 - Hosts: 61.188.38.64 13511.com
O1 - Hosts: 61.188.38.64 www.13511.com
O1 - Hosts: 61.188.38.64 ywg.cn
O1 - Hosts: 61.188.38.64 www.hyap98.com
O2 - BHO: (no name) - _{0005A87D-D626-4B3A-84F9-1D9571695F55} - (no file)
O2 - BHO: 搜索助手 - _{04844102-FC0B-4f44-9E93-0C4293BB5E80} - (no file)
O2 - BHO: (no name) - _{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: yPhtb - _{33BBE430-0E42-4f12-B075-8D21ACB10DCB} - (no file)
O2 - BHO: (no name) - _{35980F6E-A137-4E50-953D-813BB8556899} - (no file)
O2 - BHO: Anti Fish - _{38928D50-8A48-44C2-945F-D2F23F771410} - (no file)
O2 - BHO: YDragSearch - _{62EED7C6-9F02-42f9-B634-98E2899E147B} - (no file)
O2 - BHO: (no name) - _{669751ED-D558-49AE-B01A-3B374CC7910E} - (no file)
O2 - BHO: stdup - _{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - (no file)
O2 - BHO: (no name) - _{9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - _{A9930D97-9CF0-42A0-A10D-4F28836579D5} - (no file)
O2 - BHO: (no name) - _{F5824EFB-728A-4726-A5A5-85A68B20EDC3} - (no file)
O2 - BHO: (no name) - {51707E60-11C0-44FB-BAC8-83EB0C93651C} - C:\WINDOWS\system32\Feve.dll (file missing)
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O4 - HKLM\..\Run: [Corel Reminder] rem
O4 - HKLM\..\Run: [runnn] rem C:\WINDOWS\system32\xskjab.exe
O4 - HKLM\..\Run: [runn] rem C:\WINDOWS\system32\xskjad.exe
O4 - HKLM\..\Run: [Net] rem C:\WINDOWS\system32\SVCH0ST.EXE
O4 - HKLM\..\Run: [] C:\WINDOWS\system32\intenat.exe
O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\system32\wdfmgr32.exe
O4 - HKLM\..\Run: [Tray] C:\WINDOWS\command\rundll32.exe
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O9 - Extra button: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
删除
C:\WINDOWS\SYSTEM32\stdup.dll
C:\WINDOWS\system32\xskjab.exe
C:\WINDOWS\system32\xskjad.exe
C:\WINDOWS\system32\SVCH0ST.EXE
C:\WINDOWS\system32\intenat.exe
C:\WINDOWS\system32\wdfmgr32.exe
C:\WINDOWS\command\rundll32.exe
http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
处理完后...
http://forum.ikaka.com/topic.asp?board=28&artid=6979213 ⒊楼下载System Repair Engineer
解压-运行SREng.exe-智能扫描-扫描-保存日志
然后把日志内容复制上来 |
|