遭遇 unixsys08.sys/Trojan-PSW.Win32.QQPass.cdw,Trojan-PSW.Win32.OnLineGames等1
endurer 原创 2008-07-01 第1版
一位网友说他的电脑在正常模式下无法操作,于是强制重启电脑到带网络连接的安全模式,通过!!请偶帮忙检修。
下载 pe_xscan 扫描 log 并分析,发现如下可疑项: /===
pe_xscan 08-04-26 by Purple Endurer
2008-6-30 18:20:21
Windows XP Service Pack 2(5.1.2600)
MSIE:7.0.5730.13
管理员用户组
带网络连接的安全模式
[System Process] 0
2008-6-29 0:27:17
2001-6-29 0:27:8
2001-6-29 0:26:35
2001-6-29 0:26:16
2008-6-29 0:27:10
2008-6-29 0:26:59
2008-6-29 0:26:40
2008-6-29 0:26:52
2008-6-29 0:24:30
2008-6-29 0:24:14
2008-6-29 0:26:26
2008-6-29 0:26:7
2008-6-29 0:25:44
C:/WINDOWS/Explorer.EXE 1216 2004-8-7 20:0:0 Microsoft(R) Windows(R) Operating System 6.00.2900.3156 Windows Explorer (C) Microsoft Corporation. All rights reserved. 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) Microsoft Corporation ? explorer EXPLORER.EXE
2004-8-8 0:24:12
2008-6-29 0:24:14
2004-8-8 0:24:19
2008-6-29 0:24:30
2004-8-8 0:24:36
2004-8-8 0:25:44
2008-6-29 0:25:44
2004-8-8 0:25:52
2004-8-8 0:25:55
2008-6-29 0:26:1
2004-8-8 0:26:4
2008-6-29 0:26:7
2004-8-8 0:26:12
2004-8-8 0:26:17
2001-6-29 0:26:16
2004-8-8 0:26:19
2008-6-29 0:26:26
2001-6-29 0:26:35
2004-8-8 0:26:37
2008-6-29 0:26:40
2004-8-8 0:26:49
2008-6-29 0:26:52
2008-6-29 0:26:59
2001-6-29 0:27:8
2008-6-29 0:27:10
2008-6-29 0:27:17
C:/Program Files/Tencent/QQ/QQ.exe 1652 2008-2-19 6:15:10 QQ 8,0,714,1791 QQ Copyright (C) 1998 - 2008 TENCENT Inc. All Rights Reserved 8,0,714,1791 TENCENT COMQQD QQ.exe
2001-6-29 0:27:8
2001-6-29 0:26:35
2001-6-29 0:26:16
2008-6-29 0:27:10
2008-6-29 0:26:59
2008-6-29 0:26:52
2008-6-29 0:26:40
2008-6-29 0:24:30
2008-6-29 0:24:14
2008-6-29 0:26:26
2008-6-29 0:26:7
2008-6-29 0:25:44
2008-6-29 0:27:17
C:/Program Files/Tencent/QQ/TXPlatform.exe 1680 2007-11-18 1:53:39 TM2008 1, 0, 170, 201 TM2008 Copyright (C) 1998-2007 TENCENT Inc. All Rights Reserved 1, 0, 170, 0 Tencent ?
2001-6-29 0:27:8
2001-6-29 0:26:35
2001-6-29 0:26:16
2008-6-29 0:27:10
2008-6-29 0:26:59
2008-6-29 0:26:52
2008-6-29 0:26:40
2008-6-29 0:24:30
2008-6-29 0:24:14
2008-6-29 0:26:26
2008-6-29 0:26:7
2008-6-29 0:25:44
2008-6-29 0:27:17
C:/WINDOWS/System32/ctfmon.exe 116 2004-8-7 20:0:0 Microsoft? Windows? Operating System 5.1.2600.2180 CTF Loader ? Microsoft Corporation. All rights reserved. 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Corporation ? CTFMON CTFMON.EXE
2008-6-29 0:27:17
2001-6-29 0:27:8
2001-6-29 0:26:35
2001-6-29 0:26:16
2008-6-29 0:27:10
2008-6-29 0:26:59
2008-6-29 0:26:40
2008-6-29 0:26:52
2008-6-29 0:24:30
2008-6-29 0:24:14
2008-6-29 0:26:26
2008-6-29 0:26:7
2008-6-29 0:25:44
O2 - BHO - {25FD6584-698F-BCD2-602C-698745210352} -
O2 - BHO - {32023698-6984-8541-9654-698745012523} -
O2 - BHO - {35671234-7890-ABCD-CDEF-567801237653} -
O2 - BHO - {3D698451-2015-6358-9871-2015987452D3} -
O2 - BHO - {43512378-9874-5641-1025-985420368734} -
O2 - BHO - {47AC9076-C898-B098-D098-A18319080974} -
O2 - BHO - {50940F85-F015-14F1-A05F-F69858AC6D05} -
O2 - BHO - {54FAE856-AD58-20CB-A025-CD4895FA6E45} -
O2 - BHO - {55694105-5108-9405-3695-954187462155} -
O2 - BHO - {5A069845-2036-6084-9054-6087502480A5} -
O2 - BHO - {74381DEC-D78B-43E4-BA5D-5244F669EBE4} -
O2 - BHO - {7A041F13-A111-12A3-B0CF-F99818AA68A7} -
O2 - BHO - {7C8D1401-A58D-A81C-CD24-A5915C4517C7} -
O2 - BHO - - {7E853D72-626A-48EC-A868-BA8D5E23E045} -
O2 - BHO - {7FD45A54-9875-698F-E56E-65102358FDF7} -
O2 - BHO - {87FD640A-158F-48AC-FD14-1597F14A9778} -
O2 - BHO - {B490415F-65F8-B5C5-D8BA-9405FB12054B} -
O2 - BHO - {B629FF4F-ACDB-5C90-A098-FACB3456A26B} -
O20 - AppInit_DLLs =,,,
O21 - SSODL - midimapgj(0) - {4F4F0064-71E0-4f0d-0003-708476C7815F} =
O21 - SSODL - cliconfgzx.dll(0) - {00050005-0005-0005-0005-00050005BB15} =
O21 - SSODL - catsrvwl.dll(-) - {00040004-0004-0004-0004-00040004BB15} =
O21 - SSODL - kbdswjr.dll(-) - {00120012-0012-0012-0012-00120012BB15} =
O21 - SSODL - rasdlgcq.dll(-) - {00230023-0023-0023-0023-00230023BB15} =
O23 - 服务: e130371c6a3baccb (e130371c6a3baccb) -(手动)
O23 - 服务: hbdegbbh(hbdegbbh) -(引导)
O23 - 服务: Hdv32 (Hdv32) -(手动)
O23 - 服务: heebajhj(hbdegbbh) -(引导)
O23 - 服务: pjjgkej (pjjgkej) -(引导)
O24 - ShlExecHook: [7] - {7C8D1401-A58D-A81C-CD24-A5915C4517C7} =
O24 - ShlExecHook: [MICROSOFT] - {17DFD111-BF3A-4CB4-ADB0-88FCBFE69821} =
O24 - ShlExecHook: [MICROSOFT] - {4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4} =
O24 - ShlExecHook: [MICROSOFT] - {A9895933-6636-4281-BC58-EE6DE2AF96E3} =
O24 - ShlExecHook: [5] - {5A069845-2036-6084-9054-6087502480A5} =
O24 - ShlExecHook: [MICROSOFT] - {461D2AB4-29A5-45C2-9134-D52272D3DE38} =
O24 - ShlExecHook: [5] - {55694105-5108-9405-3695-954187462155} =
O24 - ShlExecHook: [B] - {B490415F-65F8-B5C5-D8BA-9405FB12054B} =
O24 - ShlExecHook: [MICROSOFT] - {5E907A48-400E-4EA8-9792-FFAE052D59E9} =
O24 - ShlExecHook: [3] - {3D698451-2015-6358-9871-2015987452D3} =
O24 - ShlExecHook: [F] - {4F4F0064-71E0-4f0d-0003-708476C7815F} =
O24 - ShlExecHook: [5] - {00050005-0005-0005-0005-00050005BB15} =
O24 - ShlExecHook: [7] - {7A041F13-A111-12A3-B0CF-F99818AA68A7} =
O24 - ShlExecHook: [MICROSOFT] - {84143967-B645-4BFF-B873-DA1DC886E9A7} =
O24 - ShlExecHook: [B] - {B629FF4F-ACDB-5C90-A098-FACB3456A26B} =
O24 - ShlExecHook: [2] - {25FD6584-698F-BCD2-602C-698745210352} =
O24 - ShlExecHook: [3] - {32023698-6984-8541-9654-698745012523} =
O24 - ShlExecHook: [5] - {eaa21495-29ae-4e50-8ad9-a4f877c1ab85} =
O24 - ShlExecHook: [8] - {87FD640A-158F-48AC-FD14-1597F14A9778} =
O24 - ShlExecHook: [MICROSOFT] - {C0595A7E-2E2F-4B34-A83A-019270A0A464} =
O24 - ShlExecHook: [7] - {7FD45A54-9875-698F-E56E-65102358FDF7} =
O24 - ShlExecHook: [5] - {54FAE856-AD58-20CB-A025-CD4895FA6E45} =
O24 - ShlExecHook: [5] - {00040004-0004-0004-0004-00040004BB15} =
O24 - ShlExecHook: [3] - {35671234-7890-ABCD-CDEF-567801237653} =
O24 - ShlExecHook: [MICROSOFT] - {189F087F-4378-405F-85FA-37D955AD7A8C} =
O24 - ShlExecHook: [5] - {00120012-0012-0012-0012-00120012BB15} =
O24 - ShlExecHook: [4] - {43512378-9874-5641-1025-985420368734} =
O24 - ShlExecHook: [MICROSOFT] - {8C41B7F7-3168-400D-A702-0E7EFE0BA304} =
O24 - ShlExecHook: [5] - {50940F85-F015-14F1-A05F-F69858AC6D05} =
O24 - ShlExecHook: [MICROSOFT] - {81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B} =
O24 - ShlExecHook: [MICROSOFT] - {7914E0AA-ECCB-4311-B584-C49538227824} =
O24 - ShlExecHook: [4] - {47AC9076-C898-B098-D098-A18319080974} =
O24 - ShlExecHook: [5] - {00230023-0023-0023-0023-00230023BB15} =
O24 - ShlExecHook: [MICROSOFT] - {E8A3B193-77E3-4FB3-986D-F4FA4828BAFC} =
O24 - ShlExecHook: [] - {74381DEC-D78B-43E4-BA5D-5244F669EBE4} =
O26 - IFEO: QQDoctor.exe -> TASKMAN.EXE
O26 - IFEO: QQDoctorMain.exe -> TASKMAN.EXE
O26 - IFEO: SelfUpdate.exe -> TASKMAN.EXE
===/
(未完待续)
本文记录了一次解决电脑遭遇Trojan-PSW.Win32.QQPass.cdw等病毒的问题过程。通过使用pe_xscan扫描工具,在带网络连接的安全模式下检测到了多个可疑项,并进一步分析了潜在的恶意软件。
863

被折叠的 条评论
为什么被折叠?



