瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求救,中了trojan.dl.win32.qqhelper.bat瑞星查出来但杀不掉

123   2  /  3  页   跳转

求救,中了trojan.dl.win32.qqhelper.bat瑞星查出来但杀不掉

[PID: 240][C:\WINNT\System32\inetsrv\inetinfo.exe]  [Microsoft Corporation, 5.00.0984]
[PID: 1880][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\System32\unimdm.tsp]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\System32\kmddsp.tsp]  [Microsoft Corporation, 5.00.2150.1]
    [C:\WINNT\System32\ndptsp.tsp]  [Microsoft Corporation, 5.00.2143.1]
    [C:\WINNT\System32\ipconf.tsp]  [Microsoft Corporation, 5.00.2143.1]
    [C:\WINNT\System32\h323.tsp]  [Microsoft Corporation, 5.00.2195.6901]
[PID: 1348][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
    [E:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [C:\WINNT\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.16]
    [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [C:\WINNT\system32\ALSNDMGR.CPL]  [Realtek Semiconductor Corp., 2.1.09]
    [C:\WINNT\system32\LICCPA.CPL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\powercfg.cpl]  [Microsoft Corporation, 5.00.3502.6601]
    [C:\WINNT\system32\U8SMSConfig.CPL]  [, 1, 0, 0, 1]
    [C:\WINNT\system32\nvtuicpl.cpl]  [NVIDIA Corporation, 6.14.10.4403]
    [C:\WINNT\system32\NVWRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.4403]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINNT\system32\PYJJU.IME]  [北京六合源软件技术有限公司, 2, 2, 0, 4]
[PID: 936][C:\Program Files\rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.20]
    [C:\Program Files\rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [C:\Program Files\rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [C:\Program Files\rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [C:\Program Files\rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [C:\Program Files\rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
[PID: 1536][E:\Program Files\360safe\safemon\360Tray.exe]  [奇虎网, 3, 6, 4, 3001]
    [E:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [E:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 6, 0, 1001]
    [E:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 6, 3, 1001]
    [E:\Program Files\360safe\live.dll]  [360safe.com, 1, 0, 1, 1021]
[PID: 1548][E:\Program Files\360safe\antiarp\antiarp.exe]  [奇虎网, 1, 0, 0, 2001]
    [E:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
[PID: 1876][C:\WINNT\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [E:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
[PID: 1868][C:\Program Files\rising\rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.7]
    [C:\WINNT\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINNT\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINNT\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINNT\system32\MFC71CHS.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\rising\rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [C:\Program Files\rising\rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[PID: 376][C:\WINNT\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
    [E:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
[PID: 1316][E:\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [E:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [E:\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
[PID: 2180][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106]
    [E:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [C:\WINNT\system32\wdmaud.drv]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\msacm32.drv]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\msadp32.acm]  [Microsoft Corporation, 5.00.2134.1]
    [C:\Program Files\rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]

==================================
文件关联
.TXT  Error. [NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  Error. [%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINNT\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 812, C:\PROGRA~1\MI6841~1\MSSQL\BINN\SQLSERVR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1096, C:\WINNT\SYSTEM32\NVSVC32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1336, C:\WINNT\SYSTEM32\U8SMSSRV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1368, C:\WINNT\SYSTEM32\SERVERNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 980, C:\PROGRAM FILES\COMMON FILES\SYSTEM\MSSEARCH\BIN\MSSEARCH.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1632, C:\PROGRA~1\MI6841~1\MSSQL\BINN\SQLAGENT.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1536, E:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1536, E:\PROGRAM FILES\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1548, E:\PROGRAM FILES\360SAFE\ANTIARP\ANTIARP.EXE]

==================================
API HOOK
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: E:\Program Files\360safe\safemon\safemon.dll)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: E:\Program Files\360safe\safemon\safemon.dll)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

已复制扫描
高手帮看看呀谢谢
gototop
 

用SRENG删除注册表中
<{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><> [N/A]
删除服务
[AVP-SE / AVP-SE][Stopped/Disabled]
<><N/A>
[C5FD27FF / C5FD27FF][Stopped/Auto Start]
<><N/A>
[Time Windows / TIMES][Stopped/Disabled]
<><N/A>
[用友U8预警调度服务 / UFALERTSERVICE][Stopped/Auto Start]
<><N/A>
删除驱动
[New0 / New0][Stopped/Auto Start]
<\??\C:\WINNT\System32\new.sys><N/A>

修复文件关联

SRENG的使用方法在:http://forum.ikaka.com/topic.asp?board=28&artid=8270267&page=1(注意,删除服务和驱动最后一个对话框选择“否”)

删除文件
C:\WINNT\System32\new.sys
c:\winnt\system32\xifkkbgv.dll

用冰刃删除以上文件
冰刃1.22地址:http://www.onlinedown.net/soft/53325.htm

PS:你的用友软件可能不能使用了,建议重新安装下
gototop
 

找不到new.sys
这个文件呀
从起以后还是删不掉xifkkbgv.dll
这个文件呀
高手帮看看呀
gototop
 

xifkkbgv.dll先重命名再重起删除!!

找不到new.sys就进行其他操作撒

都弄完再看,有问题再说~
gototop
 

已经弄完了所有的操作
名字也改不了
还是删不掉呀
gototop
 

帮我看看呀各位朋友
gototop
 

有没有人帮看看呀
gototop
 

朋友帮看看呀
gototop
 

都没有朋友帮看看吗
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT