瑞星卡卡安全论坛
可怜的病毒受害者 - 2006-7-7 19:45:00
各位,偶家有以下病毒,瑞星杀不了,怎么办??
Trojan.Agent.ddj
Trojan.PSW.LMir.knr
Trojan.Spy.Delf.aky
Trojan.PSW.Lmir.kph
有什么办法可以解决的,告诉我,小弟在此谢过了!!
独孤豪侠 - 2006-7-7 19:47:00
瑞星报的路径在哪?
outlook1 - 2006-7-7 19:48:00
用木马克星试试
可怜的病毒受害者 - 2006-7-7 19:50:00
路径在program Files和WINDOWS里,请问怎么下载木马克星?
独孤豪侠 - 2006-7-7 19:59:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213 下载四楼的工具。扫一份日志上来。
不要重复发贴.
可怜的病毒受害者 - 2006-7-7 20:16:00
2006-07-07,19:57:02
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SKYNET Personal FireWall><C:\PROGRA~1\SkyNet\FireWall\pfw.exe> [天网]
<MINI_BFYY><; C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe> [深圳市三代科技开发有限公司]
<AddrPlus3><C:\PROGRA~1\TENCENT\AdPlus\Runner.exe C:\PROGRA~1\TENCENT\AdPlus\QAHook1.dll Rundll32> []
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<WpIMService><E:\Program Files\合纵飞线漫游\WpIMService.exe> []
<TuoTu><E:\脱兔\Tuotu\Tuotu.exe /m> []
<Torjan Program><C:\WINDOWS\WINLOGON.EXE> [CoCnCs]
<Apoint><; C:\Program Files\Apoint2K\Apoint.exe> [Alps Electric Co., Ltd.]
<CeEKEY><; C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe> [COMPAL ELECTRONIC INC.]
<CeEPOWER><; C:\Program Files\TOSHIBA\Power Management\CePMTray.exe> [COMPAL ELECTRONIC INC.]
<helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
<HotKeysCmds><; C:\WINDOWS\System32\hkcmd.exe> [Intel Corporation]
<IgfxTray><; C:\WINDOWS\System32\igfxtray.exe> [Intel Corporation]
<IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [Microsoft Corporation]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<MSPY2002><; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC> []
<PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<SysExplr><; C:\Herosoft\HeroV8\SYSEXPLR.EXE> []
<TPNF><; C:\Program Files\TOSHIBA\TouchPad\TPTray.exe> [COMPAL ELECTRONIC INC.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe 1> []
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><KB215366M.LOG> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{3FDEB171-8F86-4669-B664-69B8DB553688}><C:\WINDOWS\NotoPad.DLL> []
<{C9953583-932E-4EA1-A04B-4523AAB72C30}><C:\Program Files\Internet Explorer\PLUGINS\system.sys> []
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys> []
<{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><C:\Program Files\Internet Explorer\IEXPLORE.Dat> []
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\System32\BLACKS~1.SCR> []
可怜的病毒受害者 - 2006-7-7 20:17:00
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\jhkj\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[Rising Process Communication Center / RsCCenter]
<"E:\瑞星杀毒\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\System32\xunleibho_v4.dll, >
[CMoveCatchPic Object]
{0CF098A0-CBAC-4EFB-8451-3AFC201C7222} <C:\Program Files\xBar\xBarHelper.dll, SeekLong Technologies, Inc.>
[语音域名]
{268832F4-3C5C-47DB-91F0-C093453CFA87} <C:\Program Files\E-Go(JiuYi)\990ecn_yysm\IEToolBar.dll, 九易科技>
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <E:\腾讯QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Router Layer]
{5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, N/A>
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\System32\ssup.dll, TENCENT>
[BandIE Class]
{77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <E:\酷狗\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[DragSearch BHO]
{EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} <C:\PROGRA~1\YiSou\yisoub.dll, >
[SFP Class]
{F236CC5A-F6E4-4011-9EED-C52FDF51CE3D} <C:\WINDOWS\system32\Sbhoplin.dll, 广州众达天网技术有限公司>
[豪杰超级解霸V8]
{367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\Herosoft\HeroV8\STHSDVD.EXE, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\腾讯QQ\QQ.EXE, TENCENT>
[易趣购物]
{DE607144-AC19-424e-865A-5D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <E:\腾讯QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[百度超级搜霸]
{B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.>
[一搜工具条]
{115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} <C:\Program Files\YiSou\yisou.dll, 3721>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[语音域名]
{268832F4-3C5C-47DB-91F0-C093453CFA87} <C:\Program Files\E-Go(JiuYi)\990ecn_yysm\IEToolBar.dll, 九易科技>
[{3676996C-D8C6-4356-B4BE-3A80400C606E}]
{3676996C-D8C6-4356-B4BE-3A80400C606E} <C:\WINDOWS\system32\BOBO_A~1.OCX, 17BoBo.com>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[!搜一搜]
<res://C:\Program Files\YiSou\yisou.dll/232, N/A>
[!搜一搜(&S)]
<res://C:\Program Files\YiSou\yisou.dll/232, N/A>
[&使用暴风下载器下载]
<C:\Program Files\Ringz Studio\Storm Downloader\geturl.htm, N/A>
[上传到QQ网络硬盘]
<E:\腾讯QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
<E:\酷狗\KuGoo3\KuGoo3DownX.htm, N/A>
[发送到手机]
<C:\Program Files\xBar\xBar.htm, N/A>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<E:\腾讯QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\腾讯QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\腾讯QQ\SendMMS.htm, N/A>
[百度--MP3搜索]
<RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM, N/A>
[百度--图片搜索]
<RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM, N/A>
[百度--新闻搜索]
<RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM, N/A>
[百度--歌词搜索]
<RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM, N/A>
[百度--网页搜索]
<RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM, N/A>
[百度--词典搜索]
<RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM, N/A>
[百度--贴吧搜索]
<RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM, N/A>
[豪杰超级解霸V8实时播放]
<C:\Herosoft\HeroV8\MPURLGET.HTM, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
可怜的病毒受害者 - 2006-7-7 20:17:00
正在运行的进程
[PID: 416][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 504][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 556][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 568][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 744][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 856][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 988][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 1024][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 1244][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[C:\WINDOWS\NotoPad.DLL] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\Downloaded Program Files\Ggmnji.dll] <Tencent><4, 0, 9, 90>
[C:\WINDOWS\Downloaded Program Files\Ytdvt.dll] <Tencent><4, 0, 9, 90>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\PROGRA~1\baidu\bar\baidubar.dll] <Baidu.com, Inc.><2, 0, 2, 78>
[C:\WINDOWS\System32\xunleibho_v4.dll] <><4, 3, 2, 29>
[C:\Program Files\E-Go(JiuYi)\990ecn_yysm\IEToolBar.dll] <九易科技><1, 0, 0, 15>
[C:\WINDOWS\System32\SRDLL.dll] <广州九易咨讯科技有限公司><1, 0, 1, 1>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] <Yahoo! China><1, 1, 2, 1034>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] <Yahoo!><2, 1, 3, 1043>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] <><1, 2, 7, 1006>
[E:\酷狗\KuGoo3\KuGoo3DownXControl.ocx] <N/A><N/A>
[C:\PROGRA~1\YiSou\yisoub.dll] <><1, 1, 2, 4>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[E:\瑞星杀毒\Rising\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[PID: 1288][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 1396][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[PID: 172][C:\PROGRA~1\SkyNet\FireWall\pfw.exe] <天网><2.7.3.1100>
[C:\PROGRA~1\SkyNet\FireWall\SKYMISC.DLL] <N/A><N/A>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\WINDOWS\Downloaded Program Files\Ggmnji.dll] <Tencent><4, 0, 9, 90>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 300][C:\WINDOWS\WINLOGON.EXE] <CoCnCs><0.00.0079>
[C:\WINDOWS\KB215366M.LOG] <N/A><N/A>
[C:\WINDOWS\Downloaded Program Files\Ggmnji.dll] <Tencent><4, 0, 9, 90>
[C:\Program Files\Internet Explorer\PLUGINS\system.sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] <N/A><N/A>
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] <N/A><N/A>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[E:\梦幻西游\update.1.5.90.wdf] <X1Q><8.00>
可怜的病毒受害者 - 2006-7-7 20:18:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE Error. [winfiles]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
独孤豪侠 - 2006-7-7 20:19:00
<Torjan Program><C:\WINDOWS\WINLOGON.EXE> [CoCnCs]
晕,就这个就够你玩的了.
可怜的病毒受害者 - 2006-7-7 20:23:00
那怎么办????有什么办法可以解决吗?
独孤豪侠 - 2006-7-7 20:23:00
http://forum.ikaka.com/topic.asp?board=28&artid=7678628
参考这个慢慢来吧.
否则只有格C盘重装系统.
如果照那个贴删掉后
建议你下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子优化王”“专业卸载,卸载所有提示的垃圾软件,卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。
可怜的病毒受害者 - 2006-7-7 20:30:00
木马文件指哪些?你看日志给我写下,我不知道,谢谢了
独孤豪侠 - 2006-7-7 20:33:00
我上在的那个贴子里就是针能这个木马的.
你照那一步一步做就行了.
有的没有就跳过.
可怜的病毒受害者 - 2006-7-7 20:51:00
WINLOGON.EXE进程无法结束掉
图里的木马文件没找到
找不到他那个名字的注册表修复工具
更不用说找到注册表编辑器了
可怜的病毒受害者 - 2006-7-7 21:04:00
注册表编辑器在哪
applechen - 2006-7-8 0:59:00
点左下角开始》运行》输入REGEDIT按回车就可以看到了
菰僤啲嫙箻 - 2006-7-8 12:58:00
晕!
高手就是高手...
不信天有情 - 2006-7-27 17:39:00
我觉的你是用了 外挂造成的吧(特别是免费的 如 勇者传世吉祥天破解等 )那些好多恶意木马 我都搞怕了
1
© 2000 - 2026 Rising Corp. Ltd.