瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请问如何清除新病毒:Trojan.RootKit.Vanti.bm

12   2  /  2  页   跳转

请问如何清除新病毒:Trojan.RootKit.Vanti.bm

[C:\Program Files\Common Files\Teleca Shared\Telecalib_logging.dll]  <Teleca/Popwire AB><1, 0, 2, 3>
    [C:\Program Files\Common Files\Teleca Shared\boost_log-vc71-mt-1_32.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt.dll]  <Teleca Software Solutions><1, 0, 1, 1>
    [C:\Program Files\Sony Ericsson\Mobile2\Device Manager\SpecificMPM.dll]  <SonyEricsson><1, 0, 2, 1>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Teleca Shared\SpecificUSB.dll]  <Teleca Software Solutions><1, 0, 0, 0>
[PID: 2008][C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe]  <Sony Ericsson Mobile Communications AB><1, 2, 0,1171>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ShowMfcDialog.dll]  <Sony Ericsson Mobile Communications AB><1, 0, 0,101>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll]  <N/A><N/A>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msmeirsock_object.dll]  <Sony Ericsson Mobile Communications AB><1, 0, 0,925>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ms98irsock_object.dll]  <Sony Ericsson Mobile Communications AB><1, 0, 0,970>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cellphone_object.dll]  <Sony Ericsson Mobile Communications AB><1, 0, 0,1175>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsmoddata.dll]  <Sony Ericsson Mobile Communications AB><1, 2, 0,289>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msirsock_object.dll]  <Sony Ericsson Mobile Communications AB><1, 0, 0,982>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cabmain.dll]  <Sony Ericsson Mobile Communications AB><1, 0, 0,1207>
    [C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\xpbtsock_2_object.dll]  <Sony Ericsson Mobile Communications AB><1, 0, 0,118>
[PID: 896][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3152][D:\BitSpirit\BitSpirit.exe]  <LANSPIRIT.NET><3.0.0.87>
    [D:\BitSpirit\plugin\peerid.dll]  <N/A><N/A>
    [D:\BitSpirit\plugin\tracker.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 4056][D:\TouchNet\TouchNet.exe]  <TouchingSoft.com><1, 0, 0, 0>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 4016][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 1924][D:\FlashGet\flashget.exe]  <Amaze Soft><1, 6, 5, 0>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 3672][C:\Downloads\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

请不言给看看,如有问题请告之.谢谢!
gototop
 

不错
xpnq28t.dll木马已经不见了

进入注册表
删除
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NTdhcp><; >

退出注册表
删除C:\WINDOWS\system32\NTdhcp.exe
gototop
 

我也是看了你相关的帖子才清除成功的,再次感谢不言!有事会再扰你的.
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT