瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】 这到底是啥啊 怎样弄阿 请帮帮我

1   1  /  1  页   跳转

【求助】 这到底是啥啊 怎样弄阿 请帮帮我

【求助】 这到底是啥啊 怎样弄阿 请帮帮我

Trojan.PSW.Lmir.ipq  这个病毒我用瑞星最新版本  DOS杀毒  叶用了  木马克星杀毒了
可是每当机器从起后病毒依然存在  请各位高手  师傅帮忙想想办法把
C:\WINDOWS\system32\wininet32.DLL  这个是不是路径阿  我也找不到这个文件
到底该怎末办啊  期盼路过的高手帮忙想想办法啊  我就在这里等了
谢谢了  谢谢了
最后编辑2005-10-15 13:49:20
分享到:
gototop
 

用HijackThis扫描系统,然后把日志贴上来

HijackThis下载地址:
http://forum.ikaka.com/topic.asp?board=67&artid=5188931

HijackThis的使用方法:
http://it.rising.com.cn/newSite/Channels/anti_virus/Antivirus_Faq/TopicExplorerPagePackage/hijackthis.htm
gototop
 

o  谢谢阿  我看看
gototop
 


* HijackThis v1.97 *
原作者邮箱:merijn@spywareinfo.com    汉化人:Qoo酷儿
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
http://www.spywareinfo.com/~merijn/index.html

汉化声明:酷儿仅仅汉化HijackThis的界面,版权仍归原作者所有 !本汉化只为了方便使用,但不对任何使用上问题负责!

*** 查看本软件版本更新历史 ***
[v1.96]
* Lots of bugfixes and small enhancements! Among others:
* Fix for Japanese IE toolbars
* Fix for searchwww.com fake CLSID trick in IE toolbars and BHO's
* O19 (user stylesheet) now only checks for known bad filenames
* Attributes on Hosts file will now be restored when scanning/fixing/restoring it.
* Added several files to the LSP whitelist
* Fixed some issues with incorrectly re-encrypting data, making R0/R1 go undetected until a restart
* All sites in the Trusted Zone are now shown, with the exception of those on the nonstandard but safe domain list
[v1.95]
* Added a new regval to check for from Whazit hijack (Start Page_bak).
* Excluded IE logo change tweak from toolbar detection (BrandBitmap and SmBrandBitmap).
* New in logfile: Running processes at time of scan.
* Checkmarks for running StartupList with /full and /complete in HijackThis UI.
* New O19 method to check for Datanotary hijack of user stylesheet.
* Google.com IP added to whitelist for Hosts file check.
[v1.94]
* Fixed a bug in the Check for Updates function that could cause corrupt downloads on certain systems.
* Fixed a bug in enumeration of toolbars (Lop toolbars are now listed!).
* Added imon.dll, drwhook.dll and wspirda.dll to LSP safelist.
* Fixed a bug where DPF could not be deleted.
* Fixed a stupid bug in enumeration of autostarting shortcuts.
* Fixed info on Netscape 6/7 and Mozilla saying '%shitbrowser%' (oops).
* Fixed bug where logfile would not auto-open on systems that don't have .log filetype registered.
* Added support for backing up F0 and F1 items (d'oh!).
[v1.93]
* Added mclsp.dll (McAfee), WPS.DLL (Sygate Firewall), zklspr.dll (Zero Knowledge) and mxavlsp.dll (OnTrack) to LSP safelist.
* Fixed a bug in LSP routine for Win95.
* Made taborder nicer.
* Fixed a bug in backup/restore of IE plugins.
* Added UltimateSearch hijack in O17 method (I think).
* Fixed a bug with detecting/removing BHO's disabled by BHODemon.
* Also fixed a bug in StartupList (now version 1.52.1).
[v1.92]
* Fixed two stupid bugs in backup restore function.
* Added DiamondCS file to LSP files safelist.
* Added a few more items to the protocol safelist.
* Log is now opened immediately after saving.
* Removed rd.yahoo.com from NSBSD list (spammers are starting to use this, no doubt spyware authors will follow).
* Updated integrated StartupList to v1.52.
* In light of SpywareNuker/BPS Spyware Remover, any strings relevant to reverse-engineers are now encrypted.
* Rudimentary proxy support for the Check for Updates function.
[v1.91]
* Added rd.yahoo.com to the Nonstandard But Safe Domains list.
* Added 8 new protocols to the protocol check safelist, as well as showing the file that handles the protocol in the log (O18).
* Added listing of programs/links in Startup folders (O4).
* Fixed 'Check for Update' not detecting new versions.
[v1.9]
* Added check for Lop.com 'Domain' hijack (O17).
* Bugfix in URLSearchHook (R3) fix.
* Improved O1 (Hosts file) check.
* Rewrote code to delete BHO's, fixing a really nasty bug with orphaned BHO keys.
* Added AutoConfigURL and proxyserver checks (R1).
* IE Extensions (Button/Tools menuitem) in HKEY_CURRENT_USER are now also detected.
* Added check for extra protocols (O18).
[v1.81]
* Added 'ignore non-standard but safe domains' option.
* Improved Winsock LSP hijackers detection.
* Integrated StartupList updated to v1.4.
[v1.8]
* Fixed a few bugs.
* Adds detecting of free.aol.com in Trusted Zone.
* Adds checking of URLSearchHooks key, which should have only one value.
* Adds listing/deleting of Download Program Files.
* Integrated StartupList into the new 'Misc Tools' section of the Config screen!
[v1.71]
* Improves detecting of O6.
* Some internal changes/improvements.
[v1.7]
* Adds backup function! Yay!
* Added check for default URL prefix
* Added check for changing of IERESET.INF
* Added check for changing of Netscape/Mozilla homepage and default search engine.
[v1.61]
* Fixes Runtime Error when Hosts file is empty.
[v1.6]
* Added enumerating of MSIE plugins
* Added check for extra options in 'Advanced' tab of 'Internet Options'.
[v1.5]
* Adds 'Uninstall & Exit' and 'Check for update online' functions.
* Expands enumeration of autoloading Registry entries (now also scans for .vbs, .js, .dll, rundll32 and service)
[v1.4]
* Adds repairing of broken Internet access (aka Winsock or LSP fix) by New.Net/WebHancer
* A few bugfixes/enhancements
[v1.3]
* Adds detecting of extra MSIE context menu items
* Added detecting of extra 'Tools' menu items and extra buttons
* Added 'Confirm deleting/ignoring items' checkbox
[v1.2]
* Adds 'Ignorelist' and 'Info' functions
[v1.1]
* Supports BHO's, some default URL changes
[v1.0]
* Original release

请你在HijackThis版本更新前,先清空你的忽略列表,这是因为新版本可能不兼容旧版本的忽略列表!注意:酷儿汉化的只为当前版本[HijackThis1.97.7],当你更新版本后,此汉化版本将不可用!当然,若新版本提供更多功能,酷儿也将同步更新,汉化新的版本,请留意

以下部分,酷儿将简单介绍本软件在各个分类的说明,希望为大家提供一个参考!(以下部分参考“风之咏者”提供的翻译,在此感谢“风之咏者”“baohe”等人的翻译帮助!)       
R – 注册表中的默认起始主页和默认搜索页的改变                 
    R0 - 默认主页被改               
    R1 - 新建的注册表值(V),或称为键值     
    R2 - 新建的注册表项(K),或称为键   
    R3 - 在本来应该只有一个键值的地方新建的额外键值                               
F - ini文件中的自动运行程序。             
    F0 - ini文件中改变的值         
    F1 - ini文件中新建的值         
N - Netscape、Mozilla浏览器的默认起始主页和默认搜索页的改变。       
    N1 - Netscape 4.x中,prefs.js的改变。       
    N2 - Netscape 6中,prefs.js的改变。       
    N3 - Netscape 7中,prefs.js的改变。       
    N4 - Mozilla中,prefs.js的改变。       
O - 其它类,包含很多方面,下面一一详述。                   

    O1 - 在Host文件中将默认搜索页重新定向。                         
    O2 - 列举现有的IE浏览器的BHO模块。               
    O3 - 列举现有的IE浏览器的工具条。                     
    O4 - 列举自启动项                                               
    O5 - 控制面板中被屏蔽的一些IE选项                                     
    O6 - Internet选项被禁用。                                       
    O7 - 注册表编辑器(regedit)                 
    O8 - IE的右键菜单中的新增项目               
    O9 - 额外的IE“工具”菜单项目及工具栏按钮。             
    O10 - Winsock LSP浏览器“劫持”。                               
    O11 - IE的高级选项中的新项目。                               
    O12 - IE插件。                                       
    O13 - 对IE默认的URL前缀的修改               
    O14 - IERESET.INF文件中的改变。   
    O15 - “受信任的站点”中的不速之客     
    O16 - 下载的程序文件。                 
    O17 - 域“劫持”     

    O18 - 列举现有的协议(protocols)             
    O19 - 用户样式表(stylesheet)“劫持”

  你也可以在扫描列表选定该项目,并点击“关于该选项的帮助信息”,得到该项目的详细帮助信息 ! 
    “问世间情为何物,直教人生死相许!”--献给我永远深爱的薇薇,衷心祝愿她婚姻永远微笑!                    永远是薇薇的守护天使 -- YHM 汉化于2004年02月29日      ming-yhm@sohu.com
到这里我还是不知道该怎样弄了  能告诉我下一步该怎样弄吗
gototop
 

我不知道该怎样修复阿
gototop
 

进入hijackthis,选Do a scan and save a log ,然后把记事本中的log 贴上来。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT