瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 急!!~用卡卡查出的未知病毒!!清除不掉!【求助】

12   2  /  2  页   跳转

急!!~用卡卡查出的未知病毒!!清除不掉!【求助】

[PID: 4040 / wangli][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\system32\IEFRAME.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\Windows-Ghost.dll]  [N/A, ]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\IEUI.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [c:\documents and settings\administrator.microsof-88bb49\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [C:\Program Files\Internet Explorer\ieproxy.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 7, 15]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll]  [, 1, 0, 0, 8]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 11]
    [C:\WINDOWS\system32\ieapfltr.dll]  [Microsoft Corporation, 7.0.6000.16461]
    [d:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
    [D:\Program Files\Real\RealPlayer\rpplugins\embd3260.dll]  [RealNetworks, Inc., 6.0.12.1739]
    [C:\Program Files\Common Files\Real\Common\pngu3267.dll]  [RealNetworks, Inc., 6.7.0.2962]
    [C:\Program Files\Common Files\Real\Common\pnrs3260.dll]  [RealNetworks, Inc., 6.0.9.4317]
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  [RealNetworks, Inc., 0.1.0.6726]
    [D:\Program Files\Real\RealPlayer\rpplugins\rpcl3260.dll]  [RealNetworks, Inc., 6.0.9.3362]
    [D:\Program Files\Real\RealPlayer\rpplugins\rput3260.dll]  [RealNetworks, Inc., 6.0.9.3363]
    [C:\Program Files\Common Files\Real\Common\pnen3260.dll]  [RealNetworks, Inc., 10.0.0.1283]
    [C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll]  [RealNetworks, Inc., 10.1.0.1180]
    [C:\Program Files\Common Files\Real\Plugins\zipf3260.dll]  [RealNetworks, Inc., 6.0.8.2799]
    [C:\Program Files\Common Files\Real\Plugins\vidsite.dll]  [RealNetworks, Inc., 10.0.0.1253]
    [C:\Program Files\Common Files\Real\Plugins\clntxres.dll]  [RealNetworks, Inc., 10.0.0.4181]
    [D:\Program Files\Real\RealPlayer\lang\cdplay_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\dbcomp_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\embed_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\gemctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\pngui_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\pdgenxfer_cn.dll]  [N/A, ]
    [D:\Program Files\Real\RealPlayer\lang\rjctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjeq_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjres_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjskin_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjviz_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjfade_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjdlg_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjmisc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rjprog_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rpapp_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [D:\Program Files\Real\RealPlayer\lang\rpclsvc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rpclutil_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [D:\Program Files\Real\RealPlayer\lang\rpdemand_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [D:\Program Files\Real\RealPlayer\lang\rpdsplyr_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rpgutil_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rpmnpane_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rpplylst_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\rpwebctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\tcdinfo_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\tclsvc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\tdwnmgr_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\tmp3_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\twave_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\teasdk_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\tearm_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\tmdedit_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [D:\Program Files\Real\RealPlayer\lang\mydevices_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [C:\Program Files\Common Files\Real\Plugins\memfsys.dll]  [RealNetworks, Inc., 10.0.0.1219]
    [C:\Program Files\Common Files\Real\Plugins\pacplin.dll]  [RealNetworks, Inc., 10.0.0.1253]
    [C:\Program Files\Common Files\Real\Plugins\authmgr.dll]  [RealNetworks, Inc., 10.0.0.1687]
    [C:\Program Files\Common Files\Real\Plugins\ramfformat.dll]  [RealNetworks, Inc., 10.0.0.2477]
    [C:\Program Files\Common Files\Real\Plugins\rmfformat.dll]  [RealNetworks, Inc., 10.0.0.1475]
    [D:\Program Files\Real\RealPlayer\rpplugins\rpap3260.dll]  [RealNetworks, Inc., 6.0.9.3301]
    [C:\Program Files\Common Files\Real\Plugins\httpfsys.dll]  [RealNetworks, Inc., 10.0.0.3032]
    [C:\Program Files\Common Files\Real\Plugins\rarender.dll]  [RealNetworks, Inc., 10.0.0.1260]
    [C:\Program Files\Common Files\Real\Plugins\rvrender.dll]  [RealNetworks, Inc., 10.0.0.1644]
    [C:\Program Files\Common Files\Real\Plugins\smmrender.dll]  [RealNetworks, Inc., 10.0.0.1250]
[PID: 1612 / wangli][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\system32\IEFRAME.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\Windows-Ghost.dll]  [N/A, ]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\IEUI.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\xmllite.dll]  [Microsoft Corporation, 1.00.1018.0]
    [c:\documents and settings\administrator.microsof-88bb49\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [D:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\Internet Explorer\ieproxy.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.4]
    [D:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.2.9]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 7, 15]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll]  [, 1, 0, 0, 8]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 11]
    [C:\WINDOWS\system32\ieapfltr.dll]  [Microsoft Corporation, 7.0.6000.16461]
    [d:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
gototop
 

[PID: 2164 / wangli][d:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [C:\WINDOWS\Windows-Ghost.dll]  [N/A, ]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [d:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 3240 / wangli][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
    [C:\WINDOWS\Windows-Ghost.dll]  [N/A, ]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2756 / wangli][D:\Downloads\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\Windows-Ghost.dll]  [N/A, ]
    [D:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [D:\Downloads\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 568, D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 804, D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 804, D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1188, D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1188, D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1216, C:\WINDOWS\VM30XSNAP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1216, C:\WINDOWS\VM30XSNAP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1144, D:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1144, D:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2164, D:\PROGRAM FILES\RISING\RAV\RSAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2164, D:\PROGRAM FILES\RISING\RAV\RSAGENT.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

我装了斑竹所说的软件
也提示我有同样的进程
报告如上
请斑竹大人过目
对了
我用瑞星全盘查杀过
什么都没杀到
只有卡卡可以查到
而这些未知病毒
在安全模式下又查不到
gototop
 

再附个图

附件附件:

下载次数:215
文件类型:image/pjpeg
文件大小:
上传时间:2007-9-8 20:25:24
描述:



gototop
 

安全模式下(开机后不断 按F8键  然后出来一个高级菜单 选择第一项 安全模式 进入系统)

打开sreng (就是你扫日志的软件)

“启动项目”-“服务”-“Win32服务应用程序”中点“隐藏经认证的微软项目”,
选中以下项目,点“删除服务”,再点“设置”,在弹出的框中点“否”:
Windows-Ghost / Windows-Ghost

双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹" 并清除"隐藏受保护的操作系统文件(推荐)"前面的钩。在提示确定更改时,单击“是” 然后确定
点击  菜单栏下方的 文件夹按钮(搜索右边的按钮)
在左边的资源管理器中单击C盘(千万不要双击打开)
删除如下文件C:\WINDOWS\Windows-Ghost.exe
C:\WINDOWS\Windows-Ghost.dll
gototop
 

斑竹大人你真是太有才了!!!!
非常感谢!!!!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT