光之迷影 - 2006-9-19 21:45:00
Trojan.Scamp.a
请问这个是病毒吗?瑞星老是提示说是病毒.但是这个文件册不掉.
光之迷影 - 2006-9-19 21:47:00
文件路经是C:\Program Files\Common Files\IE-Bar
光之迷影 - 2006-9-19 21:53:00
2006-09-04,04:15:25
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><; C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []
<Super Rabbit IEPro><D:\网络快车\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []
<WinTelnet><C:\WINDOWS\system32\WinServer.exe> []
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<RavScanBD><; "F:\Program Files\Rising\Rav\ScanBD.exe" /INST> [Beijing Rising Technology Co., Ltd.]
<RavTask><; "F:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
服务
[RsRavMon Service / RsRavMon]
<"F:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\网络快车\MagicSet\haokanbar.dll, Xiang Feng Technology>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\网络快车\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\网络快车\MagicSet\haokanbar.dll, Xiang Feng Technology>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\网络快车\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[使用网际快车下载]
<D:\网络快车\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\网络快车\FlashGet\jc_all.htm, N/A>
光之迷影 - 2006-9-19 21:53:00
正在运行的进程
[PID: 536][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 600][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 624][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 668][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 848][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 944][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1036][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1084][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1240][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1460][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\Rsvtub.dll] <N/A><N/A>
[F:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1552][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1648][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.06>
[PID: 1656][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3512>
[PID: 1664][C:\WINDOWS\system32\Realplayer.exe] <N/A><N/A>
[PID: 1672][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1692][D:\网络快车\MagicSet\SRIECLI.EXE] <Super Rabbit Soft><7.76>
[D:\网络快车\MagicSet\shlobj71.ocx] <Sky Software (http://www.ssware.com)><7, 1, 0, 0>
[PID: 1212][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1884][F:\Program Files\Rising\Rav\RsAgent.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[F:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 1872][C:\WINDOWS\msagent\AgentSvr.exe] <Microsoft Corporation><2.00.0.3422>
[PID: 1356][F:\Program Files\Rising\Rav\RavMon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[F:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 25>
[F:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[F:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[F:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[F:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[F:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[F:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1144][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 980][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\网络快车\MagicSet\haokanbar.dll] <Xiang Feng Technology><2, 2, 0, 1612>
[C:\WINDOWS\system32\macromed\flash\flash.ocx] <Macromedia, Inc.><6,0,79,0>
[PID: 2624][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\网络快车\MagicSet\haokanbar.dll] <Xiang Feng Technology><2, 2, 0, 1612>
[C:\WINDOWS\system32\macromed\flash\flash.ocx] <Macromedia, Inc.><6,0,79,0>
[PID: 2108][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[D:\网络快车\MagicSet\haokanbar.dll] <Xiang Feng Technology><2, 2, 0, 1612>
[PID: 3348][D:\小说\sreng2\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
光之迷影 - 2006-9-19 21:55:00
那位有空帮我看看.谢谢..菜鸟:)
光之迷影 - 2006-9-19 22:24:00
那位高手..帮我看下嘛..没问题也告诉我声.
deadmanzj - 2006-9-19 22:36:00
<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []参考置顶,下载专杀
<WinTelnet><C:\WINDOWS\system32\WinServer.exe> []这个文件打包加密123发送到gudugd@yahoo.com.cn(删除前先打包)
打开SREng 启动项目 注册表 删除
<WinTelnet><C:\WINDOWS\system32\WinServer.exe> []
删除
C:\WINDOWS\system32\WinServer.exe
C:\Program Files\Common Files\IE-Bar里面有个卸载程序,卸掉后,删除这个文件夹
无奈的笨丫丫 - 2006-9-20 16:42:00
楼上的那位高手
我很菜的,你写的我看不懂
帮帮我,好吗?
基本零起点 - 2006-9-20 18:05:00
| 引用: |
【无奈的笨丫丫的贴子】楼上的那位高手 我很菜的,你写的我看不懂 帮帮我,好吗? ……………… |
6楼的意思是:
1、<Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe> []这一项可以参考本论坛置顶的帖子,有具体的下载专门杀毒办法。

2、让你把 <WinTelnet><C:\WINDOWS\system32\WinServer.exe> []这个文件打包发到6楼的信箱,他要研究用。

3、建议你先去下一个SREng,然后打开SREng ,在启动项目 注册表 删除
<WinTelnet><C:\WINDOWS\system32\WinServer.exe> [] 下载地址6楼朋友的盘里可能有。或者你去论坛找找。
4、删除
C:\WINDOWS\system32\WinServer.exe
C:\Program Files\Common Files\IE-Bar里面有个卸载程序,卸掉后,删除这个文件夹

6楼朋友说的大概就是这个意思了~~

下班咧~~
pippo仔 - 2006-9-27 10:04:00
IE -BAR可以用其自带的卸载程序来卸载,它卸载时需要输入验证码,这个验证码就在卸载对话框上。笔者的计算机不小心被安装上DeskMedia后,用优化大师和超级兔子卸载后,重启后又在计算机中发现IE-BAR,在安全模式下清除后,开机正常启动后又出现IE-BAR。用它自带的反而一次成功。
© 2000 - 2026 Rising Corp. Ltd.