瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 红夜鬼GG,病毒杀不了....不好意思,又要麻烦您了..

12   2  /  2  页   跳转

红夜鬼GG,病毒杀不了....不好意思,又要麻烦您了..

[C:\Program Files\Globallink\Game\share\OurFriend\ODCtrlRes.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Globallink\Game\share\OurFriend\ourfriend_res.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\GLPNG.dll]  [globallink(ourgame) , 1, 0, 0, 2]
    [C:\WINDOWS\system32\GLCOMPRESS.dll]  [globallink, 1, 0, 0, 2]
    [C:\Program Files\Globallink\Game\share\roomicon.dll]  [Beijing GlobalLink Computer Corp., 2, 5, 0, 6]
    [C:\Program Files\Globallink\Game\share\RIconEx.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 1, 40]
    [C:\Program Files\Globallink\Game\share\people.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 3]
    [C:\Program Files\Globallink\Game\share\Image\Room\Table0.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Table1.dll]  [Beijing GlobalLink Computer Corp., 2, 1, 2, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Table2.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx0.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx1.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx2.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx3.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx4.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx5.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx6.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx7.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx8.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx9.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx10.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx11.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx12.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx13.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 2]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx14.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\peopleEx15.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_0.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_1.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_2.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_3.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_4.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_5.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_6.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_7.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_8.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_9.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_10.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_11.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 0, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_12.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_13.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_14.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player0_15.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_0.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_1.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_2.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_3.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_4.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_5.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_6.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_7.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_8.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_9.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_10.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_11.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_12.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_13.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_14.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player1_15.dll]  [Beijing GlobalLink Computer Corp., 2, 2, 0, 1]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_0.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_1.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_2.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
gototop
 

[C:\Program Files\Globallink\Game\share\Image\Room\Player2_3.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_4.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_5.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_6.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_7.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_8.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_9.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_10.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_11.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_12.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_13.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_14.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\Program Files\Globallink\Game\share\Image\Room\Player2_15.dll]  [Beijing GlobalLink Computer Corp., 2, 0, 1, 255]
    [C:\PROGRA~1\GLOBAL~1\Game\share\GLAvatar.ocx]  [, 2, 2, 0, 32]
    [c:\program files\globallink\game\share\glacm.dll]  [N/A, N/A]
    [C:\PROGRA~1\GLOBAL~1\Game\share\GLChatEx.ocx]  [GlobalLink, 2, 5, 1, 29]
    [C:\PROGRA~1\GLOBAL~1\Game\share\glchatex.dll]  [GlobalLink, 2, 5, 1, 29]
    [C:\PROGRA~1\GLOBAL~1\Game\share\odctrls\ourfriend_skn.dll]  [, 1, 0, 5, 4]
    [C:\WINDOWS\system32\codecvt.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\GLGIFTGA.dll]  [globallink(ourgame) , 1, 0, 0, 2]
[PID: 2052][C:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
    [c:\program files\globallink\game\share\glacm.dll]  [N/A, N/A]
[PID: 2064][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3422]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
[PID: 2368][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
    [c:\program files\globallink\game\share\glacm.dll]  [N/A, N/A]
[PID: 1992][C:\DOCUME~1\clk\LOCALS~1\Temp\Rar$EX00.109\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
    [c:\program files\globallink\game\share\glacm.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A
gototop
 

运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
Network Security 

,选择“删除服务”
点“设置”选择“否”

运行(双击)SRENG2,点“启动项目,服务,点“驱动程序”
勾选“隐藏微软服务”选中病毒服务
mohm
,选择“删除服务”
点“设置”选择“否”
重启按F8进入安全模式下修复
显示隐藏文件
删除:     
C:\WINDOWS\system32\csjufd89.dll
C:\WINDOWS\system32\drivers\mohmd.sys
C:\WINDOWS\system32\cortc.ALL
c:\program files\globallink\game\share\glacm.dll
无法删除,去置贴下载冰刃删除
gototop
 

好的,谢谢,这二个肯定删除不了,C:\WINDOWS\system32\cortc.ALL/C:\WINDOWS\system32\drivers\mohmd.sys.

无法删除,去置贴下载冰刃删除(麻烦给我个下载地址好吗?)
gototop
 

Icesword v1.20(新手慎用)
①这是一斩断黑手的利刃,它适用于Windows 2000/XP/2003 操作系统,其内部功能是十分强大,用于查探系统中的幕后黑手-木马后门,并作出处理。可能您也用过很多类似功能的软件,比如一些进程工具、端口工具,但是现在的系统级后门功能越来越强,一般都可轻而易举地隐藏进程、端口、注册表、文件信息,一般的工具根本无法发现这些“幕后黑手”。IceSword 使用了大量新颖的内核技术,使得这些后门躲无所躲。当然使用它需要用户有一些操作系统的知识。使用前请详细阅读说明。
在对软件做讲解之前,首先说明第一注意事项:此程序运行时不要激活内核调试器(如softice),否则系统可能即刻崩溃。另外使用前请保存好您的数据,以防万一未知的Bug带来损失。
IceSword目前只为使用32位的x86兼容CPU的系统设计,另外运行IceSword需要管理员权限。

IceSword1.20 功能改动不大..跟 1.18 没多大区别..

②最新版本下载地址:
中文:http://202.38.64.10/~jfpan/download/IceSword120_cn.zip MD5 :cfb8514add1fbfb510b0084e837e561c

英文:http://202.38.64.10/~jfpan/download/IceSword120_en.zip MD5: 14573e30abbbe576ed739ec7866e5939

gototop
 

好吓人的,不会有事吧,我只要下载这个中文的就可以了吧?
http://202.38.64.10/~jfpan/download/IceSword120_cn.zip
gototop
 

引用:
【红夜鬼1的贴子】运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
Network Security 

,选择“删除服务”
点“设置”选择“否”

运行(双击)SRENG2,点“启动项目,服务,点“驱动程序”
勾选“隐藏微软服务”选中病毒服务
mohm
,选择“删除服务”
点“设置”选择“否”
重启按F8进入安全模式下修复
显示隐藏文件
删除:     
C:\WINDOWS\system32\csjufd89.dll
C:\WINDOWS\system32\drivers\mohmd.sys
C:\WINDOWS\system32\cortc.ALL
c:\program files\globallink\game\share\glacm.dll
无法删除,去置贴下载冰刃删除
………………


全部按照您的搞好了,就是这二个病毒:病毒名:Trojan.Spy.Popc.a
路径:
第一个::C:\WINDOWS\system32\cortc.ALL 文件名:cortc.ALL
第二个:C:\WINDOWS\system32\drivers\mohmd.sys 文件名:mohmd.
在删除时仍然这样提示:无法删除cortc.ALL 文正被另一个人或程序在使用,关闭任何可能使用这个文件的程序,重新试一次.
已经下载了冰刀,就是不知道怎么杀?打开冰刀软件后,从那儿进去把这二个可恶的无法删除的文件删除?


红GG还在吗?如果不在,请那位知道的朋友告诉教教我怎么使用冰刀好吗?我打开软件,点开"进程"里面找不到这二个文件,又点开"启动组".里面也没有这二个文件...不知道应该怎么删?
gototop
 

去文件那里找
gototop
 

....
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT