瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 rootkit.vanti.kn这个毒我搞了一天还是有,谁帮帮我?

123   2  /  3  页   跳转

rootkit.vanti.kn这个毒我搞了一天还是有,谁帮帮我?

不能删除...............
gototop
 

不能删除..............
gototop
 

不能删除................
gototop
 

不能删除?.......
gototop
 

轩辕快来啊!!!!!!!!!!!!!!!!!!!!!!!!!!!
gototop
 

轩辕人呢............................
在不在啊近来看下.......................
gototop
 

刷新后:.....................................................

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ NvMediaCenterNVIDIA Media Center LibraryNVIDIA Corporationc:\windows\system32\nvmctray.dll

+ nwizNVIDIA nView Wizard, Version 110.36 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

+ RavTimerFile not found: C:\Program Files\rising\rav\RavTimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe

+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.c:\windows\soundman.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

C:\Documents and Settings\d\「开始」菜单\程序\启动

+ 腾讯QQ.lnkQQTENCENTc:\program files\tencent\qq\qq.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

+ CheckFaultKernelc:\windows\system32\mswdm.exe

HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components

+ 0File not found: About:Home

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ new123.sysc:\program files\internet explorer\plugins\new123.sys

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ systema.dllc:\windows\system32\systema.dll

+ wddkfwgu.dllFile not found: c:\program files\rising\rav\wddkfwgu.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Desktop ExplorerNVIDIA Desktop Explorer, Version 110.36 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 110.36 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ NvCpl DesktopContext ClassNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 110.36 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Play on my TV helperNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ Google Toolbar HelperGoogle IE 客户端工具栏Google Inc.c:\program files\google\googletoolbar1.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll

+ ThunderIEHelper ClassXunLei BHOThunder Networking Technologies,LTDc:\windows\system32\xunleibho_v14.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ googletoolbar1.dllGoogle IE 客户端工具栏Google Inc.c:\program files\google\googletoolbar1.dll

+ kakatool.dllBeijing Rising Technology Co., Ltd.c:\windows\system32\kakatool.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ 腾讯QQQQTENCENTc:\program files\tencent\qq\qq.exe

HKLM\System\CurrentControlSet\Services

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe

+ RsCCenter瑞星系统通讯中心Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ ALCXSENSSensaura WDM 3D Audio DriverSensaurac:\windows\system32\drivers\alcxsens.sys

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ hooksysHooksysRisingc:\program files\rising\rav\hooksys.sys

+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys

+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys

+ mProcRsRising Personal FireWall  mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys

+ New0File not found: C:\WINDOWS\system32\new.sys

+ NpfnpfNetGroup - Politecnico di Torinoc:\windows\system32\drivers\npf.sys

+ npkcryptFile not found: C:\Program Files\tencent\QQ\npkcrypt.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 91.28 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys

+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
gototop
 

轩辕快来啊~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
gototop
 

用autoruns删除以下项目:
+ CheckFaultKernelc:\windows\system32\mswdm.exe
+ new123.sysc:\program files\internet explorer\plugins\new123.sys
+ systema.dllc:\windows\system32\systema.dll
+ New0File not found: C:\WINDOWS\system32\new.sys

+ CheckFaultKernelc:\windows\system32\mswdm.exe
这个项目的具体处理参考http://forum.ikaka.com/topic.asp?board=28&artid=8134097

其他的:
重启后删除:
C:\WINDOWS\system32\new.sys
c:\program files\internet explorer\plugins\new123.sys
c:\windows\system32\systema.dll
gototop
 

太感谢了,我先试试!!!!!!!!!!!!!!!
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT