123   1  /  3  页   跳转

发现病毒,难以清除!

发现病毒,难以清除!

早上开机,卡巴就发现了该病毒,于是点击处理.
显示重启后删除该文件,于是重启后继续显示有该病毒文件,点击处理又得重启.周而复返,卡巴看来是解决不了它.这时我试着运行程序,居然常用的一些程序全部无法运行.
于是退到安全模式下进行如下的功课了:

1.运行卡巴,本想再杀一下,结果只有个小图标出现在任务栏里,运行不了他的界面在桌面上.
2.用sreng关闭rhcwui52.dll的启动项(安全模式下显示有,正常情况下未显示有),删除rhcwui52.sys的驱动服务.
3.手动删除和重命名这两个文件显示,显示有另一个程序正在运行它,但IceSword进程没有异常,均是正常的.
查看每个正在运行的进程模块,未发现rhcwui52.dll和rhcwui52.sys的影子.
4.利用IceSword和killbox删除如下两个卡巴认为是病毒的文件.均未成功.
a.    c\windows\system32\rhcwui52.dll
b.    c\windows\system32\drivers\rhcwui52.sys
IceSword删除文件时,我也设置了:禁止运行进程
killbox也设置了:结束进程和反注册两个选项
5.上百度搜索关于卡巴显示的病毒名,未果!
6.更新绿色版Dr.web病毒库,扫描这两个文件,显示无病毒
安装了SSM,不知如何使用!!
不得已,求助各位大侠,实在是能力有限,做了这些功课还是没能清除它!!!!

附件附件:

下载次数:227
文件类型:image/pjpeg
文件大小:
上传时间:2006-10-23 10:43:54
描述:
预览信息:EXIF信息



最后编辑2006-10-23 18:33:57.827000000
分享到:
gototop
 

右键属性显示(和我的系统文件是同一时期创建的):

附件附件:

下载次数:227
文件类型:image/pjpeg
文件大小:
上传时间:2006-10-23 10:49:25
描述:
预览信息:EXIF信息



gototop
 

附上日志:




006-10-23,10:01:41

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows Server 2003 Enterprise Edition  (Build 3790)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\windows\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <WinPatrol><D:\Program Files\WinPatrol\winpatrol.exe>  [BillP 工作室]
    <Task Catcher><D:\Program Files\WinPatrol\tasktrap.exe>  [BillP Studios]
    <kis><"D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe">  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\windows\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><%SystemRoot%\system32\logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\System Safety Monitor]
    <WinlogonNotify: System Safety Monitor><SSMWinlogonEx.dll>  [(Verified)System Safety Limited]

==================================
gototop
 

启动文件夹
N/A

==================================
服务
[Autodesk Licensing Service / Autodesk Licensing Service]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[卡巴斯基互联网安全套装 6.0 / AVP]
  <D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe -r><Kaspersky Lab>
[BFNNUVGFY / BFNNUVGFY]
  <><N/A>
[GUSWVEJAM / GUSWVEJAM]
  <><N/A>
[Human Interface Device Access / HidServ]
  <C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[RaySat_3dsmax8 Server / mi-raysat_3dsmax8]
  <"D:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe"><N/A>
[NVIDIA Driver Helper Service / NVSvc]
  <C:\windows\system32\nvsvc32.exe><NVIDIA Corporation>
[Shadow System Service / ShadowSystemService]
  <C:\WINDOWS\system32\shadow\ShadowService.exe><N/A>

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ghostsec / ghostsec]
  <\??\E:\下载软件\06.08.11\病毒分析和系统修复工具\gss\ghostsec.sys><N/A>
[GWIOPM / GWIOPM]
  <\??\E:\下载软件\06.08.11\病毒分析和系统修复工具\Windows优化大师V7.6赢政天下绿色版\GWIOPM.sys><N/A>
[IP in IP Tunnel Driver / IpInIp]
  <system32\DRIVERS\ipinip.sys><N/A>
[kl1 / kl1]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[Netgroup Packet Filter / NPF]
  <system32\drivers\npf.sys><NetGroup - Politecnico di Torino>
[npkcrypt / npkcrypt]
  <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Parador / Parador]
  <\??\C:\windows\system32\drivers\parador.sys><Serial Scientific International, Inc.>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[rhcwui5 / rhcwui52]
  <\SystemRoot\System32\DRIVERS\rhcwui52.sys><N/A>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[System Safety Monitor 2.0 Core Engine / safemon]
  <\SystemRoot\system32\drivers\safemon.sys><System Safety Limited>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[snpshot / snpshot]
  <C:\windows\SYSTEM32\DRIVERS\snpshot.SYS><PowerShadow>
[TSP / TSP]
  <\??\C:\windows\system32\drivers\klif.sys><Kaspersky Lab>

==================================
浏览器加载项
[IeCatch5 Class]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\PROGRA~1\FLASHGET\jccatch.dll, FlashGet>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <E:\下载软件\06.08.11\MagicSet\haokanbar.dll, Xiang Feng Technology>
[gFlash Class]
  {F156768E-81EF-470C-9057-481BA8380DBA} <D:\PROGRA~1\FLASHGET\getflash.dll, N/A>
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\PROGRA~1\FLASHGET\flashget.exe, FlashGet.com>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <E:\下载软件\06.08.11\MagicSet\haokanbar.dll, Xiang Feng Technology>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[使用网际快车下载]
  <D:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <D:\Program Files\FlashGet\jc_all.htm, N/A>
gototop
 

正在运行的进程
[PID: 396][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 444][\??\C:\windows\system32\csrss.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 472][\??\C:\windows\system32\winlogon.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\windows\system32\SSMWinlogonEx.dll]  [System Safety Limited, 2.2.0.591]
[PID: 520][C:\windows\system32\services.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 532][C:\windows\system32\lsass.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 736][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 796][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 816][C:\windows\System32\svchost.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 976][C:\windows\system32\spoolsv.exe]  [Microsoft Corporation, 5.2.3790.346 (srv03_gdr.050610-1523)]
    [C:\windows\system32\hpzsnt10.dll]  [HP, 2.323.0.0]
[PID: 1012][C:\WINDOWS\system32\msdtc.exe]  [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
[PID: 1116][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1132][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe]  [Autodesk, 2.66.000]
[PID: 1204][D:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe]  [N/A, N/A]
[PID: 1556][C:\windows\Explorer.EXE]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.2.54.0]
    [C:\windows\system32\rhcwui52.dll]  [N/A, N/A]
    [C:\windows\system32\PATROLPRO.DLL]  [BillP Studios, 1.2.0.0]
    [D:\PROGRA~1\FLASHGET\jccatch.dll]  [FlashGet, 1, 1, 5, 0]
    [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
[PID: 1852][D:\Program Files\WinPatrol\winpatrol.exe]  [BillP 工作室, 10, 0, 3, 0]
    [C:\windows\system32\PATROLPRO.DLL]  [BillP Studios, 1.2.0.0]
[PID: 1860][D:\Program Files\WinPatrol\tasktrap.exe]  [BillP Studios, 1, 0, 0, 2
Sincerely thanks the original developer coding such a meaty ware
Chinese interface localized by LordFox(狐狸少爷)
For further assistance, contact me with
HH.Feedback@GMail.COM Not to hesitate ^_^]
    [C:\windows\system32\PATROLPRO.DLL]  [BillP Studios, 1.2.0.0]
[PID: 1880][C:\windows\system32\ctfmon.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
    [C:\windows\system32\PATROLPRO.DLL]  [BillP Studios, 1.2.0.0]
[PID: 200][C:\Program Files\internet explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
    [C:\windows\system32\PATROLPRO.DLL]  [BillP Studios, 1.2.0.0]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]
    [D:\PROGRA~1\FLASHGET\jccatch.dll]  [FlashGet, 1, 1, 5, 0]
    [E:\下载软件\06.08.11\MagicSet\haokanbar.dll]  [Xiang Feng Technology, 2, 2, 0, 1612]
    [D:\PROGRA~1\FLASHGET\getflash.dll]  [N/A, 1, 0, 0, 1]
[PID: 268][E:\下载软件\06.08.11\病毒分析和系统修复工具\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\windows\system32\PATROLPRO.DLL]  [BillP Studios, 1.2.0.0]
    [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 1148][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1188][d:\Program Files\System Safety Monitor\SSMShellUtils.exe]  [System Safety Limited, 2.2.0.591]
    [C:\windows\system32\PATROLPRO.DLL]  [BillP Studios, 1.2.0.0]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

试用这个软件吧!SRENG2
gototop
 

已经在用了,上面的日志就是用最新版sreng扫描的!1
gototop
 

正在关注,求教了,各位!!!
gototop
 

继续在线关注!!
gototop
 

在线等!!
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT